6.8
CVSSv2

CVE-2015-6660

Published: 24/08/2015 Updated: 24/12/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Form API in Drupal 6.x prior to 6.37 and 7.x prior to 7.39 does not properly validate the form token, which allows remote malicious users to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks."

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal 6.0

drupal drupal 6.13

drupal drupal 6.14

drupal drupal 6.21

drupal drupal 6.22

drupal drupal 6.29

drupal drupal 6.3

drupal drupal 6.36

drupal drupal 6.4

drupal drupal 7.0

drupal drupal 7.11

drupal drupal 7.12

drupal drupal 7.13

drupal drupal 7.2

drupal drupal 7.20

drupal drupal 7.27

drupal drupal 7.28

drupal drupal 7.37

drupal drupal 7.38

drupal drupal 7.x-dev

drupal drupal 6.1

drupal drupal 6.10

drupal drupal 6.17

drupal drupal 6.18

drupal drupal 6.19

drupal drupal 6.25

drupal drupal 6.26

drupal drupal 6.32

drupal drupal 6.33

drupal drupal 6.8

drupal drupal 6.9

drupal drupal 7.16

drupal drupal 7.17

drupal drupal 7.23

drupal drupal 7.24

drupal drupal 7.30

drupal drupal 7.33

drupal drupal 7.6

drupal drupal 7.7

drupal drupal 6.15

drupal drupal 6.16

drupal drupal 6.23

drupal drupal 6.24

drupal drupal 6.30

drupal drupal 6.31

drupal drupal 6.5

drupal drupal 6.6

drupal drupal 6.7

drupal drupal 7.14

drupal drupal 7.15

drupal drupal 7.21

drupal drupal 7.22

drupal drupal 7.29

drupal drupal 7.3

drupal drupal 7.4

drupal drupal 7.5

drupal drupal 6.11

drupal drupal 6.12

drupal drupal 6.2

drupal drupal 6.20

drupal drupal 6.27

drupal drupal 6.28

drupal drupal 6.34

drupal drupal 6.35

drupal drupal 7.1

drupal drupal 7.10

drupal drupal 7.18

drupal drupal 7.19

drupal drupal 7.25

drupal drupal 7.26

drupal drupal 7.34

drupal drupal 7.35

drupal drupal 7.36

drupal drupal 7.8

drupal drupal 7.9

Vendor Advisories

Several vulnerabilities were discovered in Drupal, a content management framework: CVE-2015-6658 The form autocomplete functionality did not properly sanitize the requested URL, allowing remote attackers to perform a cross-site scripting attack CVE-2015-6659 The SQL comment filtering system could allow a user with elevated per ...