Vulnerability Bulletins

SA-CORE-2010-002 - Drupal core - Multiple vulnerabilities

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2010-002Project: Drupal coreVersion: 5.x, 6.xDate: 2010-August-11Security risk: CriticalExploitable from: RemoteVulnerability: Multiple vulnerabilitiesDescriptionMultiple vulnerabilities and weaknesses were discovered in Drupal.OpenID authentication bypassThe OpenID module provides users the ability to login to sites using an OpenID account.The OpenID module doesnt implement all the required verifications from the OpenID 2.0 protocol and is vulnerable to a number of

More info:

https://www.drupal.org/node/880476