5
CVSSv2

CVE-2014-5019

Published: 22/07/2014 Updated: 22/07/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The multisite feature in Drupal 6.x prior to 6.32 and 7.x prior to 7.29 allows remote malicious users to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal 7.28

drupal drupal 7.0

drupal drupal 7.1

drupal drupal 7.10

drupal drupal 7.11

drupal drupal 7.12

drupal drupal 7.24

drupal drupal 7.25

drupal drupal 7.26

drupal drupal 7.27

drupal drupal 7.17

drupal drupal 7.18

drupal drupal 7.19

drupal drupal 7.2

drupal drupal 7.8

drupal drupal 7.9

drupal drupal 7.x-dev

drupal drupal 7.13

drupal drupal 7.15

drupal drupal 7.21

drupal drupal 7.23

drupal drupal 7.3

drupal drupal 7.5

drupal drupal 7.7

drupal drupal 7.14

drupal drupal 7.16

drupal drupal 7.20

drupal drupal 7.22

drupal drupal 7.4

drupal drupal 7.6

drupal drupal 6.0

drupal drupal 6.11

drupal drupal 6.12

drupal drupal 6.13

drupal drupal 6.14

drupal drupal 6.27

drupal drupal 6.28

drupal drupal 6.29

drupal drupal 6.3

drupal drupal 6.2

drupal drupal 6.20

drupal drupal 6.21

drupal drupal 6.22

drupal drupal 6.6

drupal drupal 6.7

drupal drupal 6.8

drupal drupal 6.9

drupal drupal 6.10

drupal drupal 6.15

drupal drupal 6.17

drupal drupal 6.19

drupal drupal 6.23

drupal drupal 6.25

drupal drupal 6.31

drupal drupal 6.5

drupal drupal 6.1

drupal drupal 6.16

drupal drupal 6.18

drupal drupal 6.24

drupal drupal 6.26

drupal drupal 6.30

drupal drupal 6.4

Vendor Advisories

Multiple security issues have been discovered in the Drupal content management system, ranging from denial of service to cross-site scripting More information can be found at wwwdrupalorg/SA-CORE-2014-003 For the stable distribution (wheezy), this problem has been fixed in version 714-2+deb7u5 For the testing distribution (jessie), th ...