6.8
CVE-2008-6169
- EPSS 0.57%
- Veröffentlicht 19.02.2009 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:01:44
- Erkennungen
Cross-site request forgery (CSRF) vulnerability in the Localization client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization server 5.x before 5.x-1.0-alpha5 and 6.x before 6.x-alpha2, modules for Drupal, allows remote attackers to perform unauthorized actions as administrators via unspecified vectors related to the "local translation submission interface."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Drupal ≫ Localization Client Version <= 5.x-1.0
Drupal ≫ Localization Client Version <= 6.x-1.5
Drupal ≫ Localization Client Version 5.x-1.xdev
Drupal ≫ Localization Client Version 6.x-1.0
Drupal ≫ Localization Client Version 6.x-1.1
Drupal ≫ Localization Client Version 6.x-1.2
Drupal ≫ Localization Client Version 6.x-1.3
Drupal ≫ Localization Client Version 6.x-1.4
Drupal ≫ Localization Client Version 6.x-1.xdev
Drupal ≫ Localization Server Version <= 5.x-1.0alpha4
Drupal ≫ Localization Server Version <= 6.x-1.0alpha1
Drupal ≫ Localization Server Version 5.x-1.0alpha1
Drupal ≫ Localization Server Version 5.x-1.0alpha2
Drupal ≫ Localization Server Version 5.x-1.0alpha3
Drupal ≫ Localization Server Version 5.x-1.xdev
Drupal ≫ Localization Server Version 6.x-1.xdev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.57% | 0.428 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
http://drupal.org/node/324862
http://secunia.com/advisories/32388
https://exchange.xforce.ibmcloud.com/vulnerabilities/46044