[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3291-1 drupal7 -- drupal7

ID: oval:org.secpod.oval:def:602149Date: (C)2015-06-23   (M)2022-09-22
Class: PATCHFamily: unix




Several vulnerabilities were found in drupal7, a content management platform used to power websites. CVE-2015-3231 Incorrect cache handling made private content viewed by "user 1" exposed to other, non-privileged users. CVE-2015-3232 A flaw in the Field UI module made it possible for attackers to redirect users to malicious sites. CVE-2015-3233 Due to insufficient URL validation, the Overlay module could be used to redirect users to malicious sites. CVE-2015-3234 The OpenID module allowed an attacker to log in as other users, including administrators.

Platform:
Debian 8.x
Debian 7.x
Product:
drupal7
Reference:
DSA-3291-1
CVE-2015-3231
CVE-2015-3232
CVE-2015-3233
CVE-2015-3234
CVE    4
CVE-2015-3233
CVE-2015-3232
CVE-2015-3231
CVE-2015-3234
...
CPE    3
cpe:/o:debian:debian_linux:7.x
cpe:/o:debian:debian_linux:8.x
cpe:/a:drupal:drupal:7

© SecPod Technologies