[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1930 drupal6 -- several vulnerabilities

ID: oval:org.mitre.oval:def:7333Date: (C)2009-12-15   (M)2022-10-10
Class: PATCHFamily: unix




Several vulnerabilities have been found in drupal6, a fully-featured content management framework. The Common Vulnerabilities and Exposures project identifies the following problems: Gerhard Killesreiter discovered a flaw in the way user signatures are handled. It is possible for a user to inject arbitrary code via a crafted user signature. (SA-CORE-2009-007) Mark Piper, Sven Herrmann and Brandon Knight discovered a cross-site scripting issue in the forum module, which could be exploited via the tid parameter. (SA-CORE-2009-007) Sumit Datta discovered that certain drupal6 pages leak sensitive information such as user credentials. (SA-CORE-2009-007) Several design flaws in the OpenID module have been fixed, which could lead to cross-site request forgeries or privilege escalations. Also, the file upload function does not process all extensions properly leading to the possible execution of arbitrary code. (SA-CORE-2009-008) The oldstable distribution (etch) does not contain drupal6.

Platform:
Debian 5.0
Product:
drupal6
Reference:
DSA-1930
CVE-2009-2372
CVE-2009-2373
CVE-2009-2374
CVE    3
CVE-2009-2373
CVE-2009-2374
CVE-2009-2372
CPE    1
cpe:/o:debian:debian_linux:5.0

© SecPod Technologies