Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-1576

Опубликовано: 06 мая 2009
Источник: ubuntu
Приоритет: low
CVSS2: 4.3

Описание

Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

released

5.7-1ubuntu1.2
intrepid

released

5.10-1ubuntu1.1
jaunty

released

5.15-1ubuntu1.1
karmic

not-affected

5.18-1ubuntu1
upstream

released

5.17

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

DNE

intrepid

DNE

jaunty

released

6.10-1ubuntu0.1
karmic

not-affected

upstream

released

6.11

Показывать по

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 16 лет назад

Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.

nvd
около 16 лет назад

Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.

debian
около 16 лет назад

Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.1 ...

github
больше 3 лет назад

Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.

4.3 Medium

CVSS2