6.8

CVE-2008-6169

Cross-site request forgery (CSRF) vulnerability in the Localization client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization server 5.x before 5.x-1.0-alpha5 and 6.x before 6.x-alpha2, modules for Drupal, allows remote attackers to perform unauthorized actions as administrators via unspecified vectors related to the "local translation submission interface."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Drupal ≫ Localization Client Version <= 5.x-1.0
Drupal ≫ Localization Client Version <= 6.x-1.5
Drupal ≫ Localization Client Version 5.x-1.xdev
Drupal ≫ Localization Client Version 6.x-1.0
Drupal ≫ Localization Client Version 6.x-1.1
Drupal ≫ Localization Client Version 6.x-1.2
Drupal ≫ Localization Client Version 6.x-1.3
Drupal ≫ Localization Client Version 6.x-1.4
Drupal ≫ Localization Client Version 6.x-1.xdev
Drupal ≫ Localization Server Version <= 5.x-1.0alpha4
Drupal ≫ Localization Server Version <= 6.x-1.0alpha1
Drupal ≫ Localization Server Version 5.x-1.0alpha1
Drupal ≫ Localization Server Version 5.x-1.0alpha2
Drupal ≫ Localization Server Version 5.x-1.0alpha3
Drupal ≫ Localization Server Version 5.x-1.xdev
Drupal ≫ Localization Server Version 6.x-1.xdev
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.57% 0.428
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

http://drupal.org/node/324862
Patch
Vendor Advisory
http://secunia.com/advisories/32388
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/46044