Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Drupal Prior To 4.7.8 and 5.3 Multiple Remote Vulnerabilities

Drupal is prone to multiple remote vulnerabilities:

- A cross-site request-forgery vulnerability.
- An HTTP response-splitting vulnerability.
- An HTML-injection vulnerability.
- A vulnerability that may allow an attacker to mail unpublished comments.
- An arbitrary-code-execution vulnerability.

An attacker may exploit these vulnerabilities to:

- Influence or misrepresent how web content is served, cached, or interpreted.
- Execute arbitrary code within the context of the webserver process.
- Steal cookie-based authentication credentials, allowing the attacker to launch other attacks.







 

Privacy Statement
Copyright 2009, SecurityFocus