4.3
CVSSv2

CVE-2009-2374

Published: 08/07/2009 Updated: 21/04/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Drupal 5.x prior to 5.19 and 6.x prior to 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal

Vendor Advisories

Several vulnerabilities have been found in drupal6, a fully-featured content management framework The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-2372 Gerhard Killesreiter discovered a flaw in the way user signatures are handled It is possible for a user to inject arbitrary code via a crafted user sig ...