Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions via unknown vectors, related to improper token validation for (1) cached forms and (2) forms with AHAH elements.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=459108 | |
http://www.securityfocus.com/bid/30689 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44453 | vdb entry |
http://secunia.com/advisories/31825 | third party advisory |
http://www.vupen.com/english/advisories/2008/2392 | vdb entry |
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00508.html | vendor advisory |
http://drupal.org/node/295053 | |
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00259.html | vendor advisory |
http://secunia.com/advisories/31462 | third party advisory |