6.8
CVSSv2

CVE-2010-1547

Published: 21/05/2010 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x prior to 6.x-1.4 for Drupal allow remote malicious users to hijack the authentication of administrators for requests that (1) enable a page via a q=admin/build/pages/nojs/enable/ value or (2) disable a page via a q=admin/build/pages/nojs/disable/ value.

Vulnerable Product Search on Vulmon Subscribe to Product

chaos tool suite project ctools 6.x-1.0

chaos tool suite project ctools 6.x-1.3

chaos tool suite project ctools 6.x-1.2

chaos tool suite project ctools 6.x-1.1

chaos tool suite project ctools 6.x-1.x