Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-2374

Опубликовано: 08 июл. 2009
Источник: ubuntu
Приоритет: low
CVSS2: 4.3

Описание

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

released

5.7-1ubuntu1.2
intrepid

released

5.10-1ubuntu1.1
jaunty

released

5.15-1ubuntu1.1
karmic

not-affected

5.18-1.1ubuntu2
upstream

released

5.18-1.1

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

6.12-1.1ubuntu1
hardy

DNE

intrepid

DNE

jaunty

released

6.10-1ubuntu0.1
karmic

not-affected

6.12-1.1ubuntu1
upstream

released

6.12-1.1

Показывать по

4.3 Medium

CVSS2

Связанные уязвимости

nvd
почти 16 лет назад

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

debian
почти 16 лет назад

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize ...

github
около 3 лет назад

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

4.3 Medium

CVSS2