Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x prior to 5.10 and 6.x prior to 6.4 allow remote malicious users to hijack the authentication of administrators for requests that (1) add or (2) delete user access rules.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
drupal drupal 5.4 |
||
drupal drupal 5.5 |
||
drupal drupal 6.2 |
||
drupal drupal 6.3 |
||
drupal drupal 5.2 |
||
drupal drupal 5.3 |
||
drupal drupal 6.0 |
||
drupal drupal 6.1 |
||
drupal drupal 5.0 |
||
drupal drupal 5.1 |
||
drupal drupal 5.8 |
||
drupal drupal 5.9 |
||
drupal drupal 5.6 |
||
drupal drupal 5.7 |