Vulnerability Bulletins

SA-CORE-2012-001 - Drupal core multiple vulnerabilities

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2012-001Project: Drupal coreVersion: 6.x, 7.xDate: 2012-February-01Security risk: Moderately criticalExploitable from: RemoteVulnerability: Access bypass, Cross Site Request Forgery, Multiple vulnerabilitiesDescriptionCross Site Request Forgery vulnerability in Aggregator moduleCVE: CVE-2012-0826An XSRF vulnerability can force an aggregator feed to update. Since some services are rate-limited (e.g. Twitter limits requests to 150 per hour) this could lead to a denial

More info:

https://www.drupal.org/SA-CORE-2012-001