[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1792-1 drupal6 -- multiple

ID: oval:org.secpod.oval:def:600487Date: (C)2011-05-13   (M)2022-10-10
Class: PATCHFamily: unix




Multiple vulnerabilities have been discovered in drupal, a web content management system. pod.Edge discovered a cross-site scripting vulnerability due that can be triggered when some browsers interpret UTF-8 strings as UTF-7 if they appear before the generated HTML document defines its Content-Type. This allows a malicious user to execute arbitrary javascript in the context of the web site if they"re allowed to post content. Moritz Naumann discovered an information disclosure vulnerability. If a user is tricked into visiting the site via a specially crafted URL and then submits a form from that page, the information in their form submission may be directed to a third-party site determined by the URL and thus disclosed to the third party. The third party site may then execute a cross-site request forgery attack against the submitted form. For the stable distribution , these problems have been fixed in version 6.6-3lenny1. The old stable distribution does not contain drupal and is not affected. For the unstable distribution , these problems have been fixed in version 6.11-1 We recommend that you upgrade your drupal6 package.

Platform:
Debian 5.0
Product:
drupal6
Reference:
DSA-1792-1
CVE-2009-1575
CVE-2009-1576
CVE    2
CVE-2009-1576
CVE-2009-1575
CPE    1
cpe:/o:debian:debian_linux:5.0

© SecPod Technologies