5.1
CVSSv2

CVE-2013-6385

Published: 07/12/2013 Updated: 14/01/2014
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The form API in Drupal 6.x prior to 6.29 and 7.x prior to 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote malicious users to trigger application-specific impacts such as arbitrary code execution via application-specific vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal 6.0

drupal drupal 6.1

drupal drupal 6.10

drupal drupal 6.17

drupal drupal 6.18

drupal drupal 6.19

drupal drupal 6.25

drupal drupal 6.26

drupal drupal 6.7

drupal drupal 6.8

drupal drupal 6.13

drupal drupal 6.14

drupal drupal 6.21

drupal drupal 6.11

drupal drupal 6.12

drupal drupal 6.2

drupal drupal 6.20

drupal drupal 6.27

drupal drupal 6.28

drupal drupal 6.9

drupal drupal 6.22

drupal drupal 6.3

drupal drupal 6.4

drupal drupal 6.15

drupal drupal 6.16

drupal drupal 6.23

drupal drupal 6.24

drupal drupal 6.5

drupal drupal 6.6

drupal drupal 7.0

drupal drupal 7.10

drupal drupal 7.11

drupal drupal 7.19

drupal drupal 7.2

drupal drupal 7.9

drupal drupal 7.x-dev

drupal drupal 7.12

drupal drupal 7.13

drupal drupal 7.3

drupal drupal 7.4

drupal drupal 7.23

drupal drupal 7.22

drupal drupal 7.14

drupal drupal 7.15

drupal drupal 7.5

drupal drupal 7.6

drupal drupal 7.21

drupal drupal 7.20

drupal drupal 7.1

drupal drupal 7.16

drupal drupal 7.17

drupal drupal 7.18

drupal drupal 7.7

drupal drupal 7.8

Vendor Advisories

Multiple vulnerabilities have been discovered in Drupal, a fully-featured content management framework: vulnerabilities due to optimistic cross-site request forgery protection, insecure pseudo random number generation, code execution and incorrect security token validation In order to avoid the remote code execution vulnerability, it is recommende ...