6.8
CVSSv2

CVE-2007-6752

Published: 28/03/2012 Updated: 11/04/2024
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and previous versions allows remote malicious users to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by considering the "security benefit against platform complexity and performance impact" and concluding that a change to the logout behavior is not planned because "for most sites it is not worth the trade-off.

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal 4.6.0

drupal drupal 4.6

drupal drupal 7.0

drupal drupal 5.10

drupal drupal 5.4

drupal drupal 4.6.5

drupal drupal 4.5.4

drupal drupal 6.0

drupal drupal 4.7.2

drupal drupal 4.6.10

drupal drupal 6.2

drupal drupal 5.17

drupal drupal 4.6.9

drupal drupal 5.13

drupal drupal 6.14

drupal drupal 6.24

drupal drupal 6.13

drupal drupal 4.5.0

drupal drupal 5.12

drupal drupal 6.18

drupal drupal 5.2

drupal drupal 7.3

drupal drupal 4.5.2

drupal drupal 4.7.5

drupal drupal 6.12

drupal drupal 4.6.2

drupal drupal 5.7

drupal drupal 7.8

drupal drupal 6.4

drupal drupal 4.6.8

drupal drupal 4.7.3

drupal drupal 7.5

drupal drupal 4.4

drupal drupal 5.23

drupal drupal 5.0

drupal drupal 6.11

drupal drupal 5.1_rev1.1

drupal drupal 7.10

drupal drupal 4.0

drupal drupal 4.7.10

drupal drupal 4.7.8

drupal drupal 7.6

drupal drupal 7.9

drupal drupal 5.16

drupal drupal 4.7_revision_1.2

drupal drupal 4.5.7

drupal drupal 4.4.1

drupal drupal 4.5.1

drupal drupal 4.4.2

drupal drupal 5.15

drupal drupal 4.6.3

drupal drupal 5.x

drupal drupal 5.18

drupal drupal 5.21

drupal drupal 5.22

drupal drupal 4.5.8

drupal drupal 4.6.4

drupal drupal 7.4

drupal drupal 4.7.0

drupal drupal 7.x-dev

drupal drupal 6.7

drupal drupal 4.0.0

drupal drupal 4.6.7

drupal drupal 6.22

drupal drupal 4.5.5

drupal drupal 4.7_rev1.15

drupal drupal 4.7.9

drupal drupal 4.7

drupal drupal 6.8

drupal drupal 4.7.6

drupal drupal 6.19

drupal drupal 7.11

drupal drupal 4.6.11

drupal drupal 4.1.0

drupal drupal 6.1

drupal drupal 5.6

drupal drupal 6.21

drupal drupal 6.17

drupal drupal 5.1

drupal drupal 6.5

drupal drupal 6.x-dev

drupal drupal 4.4.3

drupal drupal 5.19

drupal drupal 4.7.7

drupal drupal 4.2.0_rc

drupal drupal 5.5

drupal drupal

drupal drupal 4.5

drupal drupal 6.10

drupal drupal 6.23

drupal drupal 6.6

drupal drupal 7.1

drupal drupal 5.14

drupal drupal 5.9

drupal drupal 5.8

drupal drupal 6.15

drupal drupal 5.3

drupal drupal 6.16

drupal drupal 7.7

drupal drupal 6.3

drupal drupal 4.6.1

drupal drupal 7.2

drupal drupal 4.7.4

drupal drupal 4.7.1

drupal drupal 4.5.3

drupal drupal 5.5.

drupal drupal 4.7_rev_1.2

drupal drupal 4.4.0

drupal drupal 4.5.6

drupal drupal 5.11

drupal drupal 4.7_rev_1.15

drupal drupal 6.20

drupal drupal 4.6.6

drupal drupal 5.20

drupal drupal 6.9

Exploits

+---------------------------------------------------------------------------------------------------------------------------------------------------+ # Exploit Title : Drupal CMS 712 (latest stable release) Multiple Vulnerabilities # Date : 02-03-2012 # Author : Ivano Binetti (ivanobinetticom) # Software link : ...