Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Drupal Remote Vulnerabilities

Drupal is prone to multiple vulnerabilities, including arbitrary-file-upload, cross-site scripting, cross-site request-forgery, and privilege-escalation issues.

Attackers can exploit these issues to:

- control how the site is rendered to users
- execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site
- steal cookie-based authentication credentials
- add or delete access control rules
- edit Drupal nodes or delete files
- upload and execute arbitrary server-side script code.

These issues affect Drupal 5.x (before 5.10) and Drupal 6.x (before 6.4).







 

Privacy Statement
Copyright 2009, SecurityFocus