Get a Pentest and security assessment of your IT network.

Advisories

DRUPAL-SA-2007-017.txt

Drupal security advisory – Several parts in Drupal core are not protected against cross site request forgeries due to improper use of the Forms API, or by taking action solely on GET requests. Malicious users are able to delete comments and content revisions and disable menu items by enticing a privileged users to visit certain URLs while the victim is logged-in to the targeted site. Drupal versions 5.x below 5.2 are affected.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/58177/DRUPAL-SA-2007-017.txt

Source: https://packetstormsecurity.com/files/58177/DRUPAL-SA-2007-017.txt.html

Related posts
Advisories

LynX-adv4_SignatureDB.txt

Advisories

Secunia Security Advisory 16497

Advisories

Secunia Security Advisory 19451

Advisories

Debian Linux Security Advisory 1187-1