Vulnerability Bulletins

SA-CORE-2009-008 - Drupal core - Multiple vulnerabilities

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2009-008Project: Drupal coreVersion: 5.x, 6.xDate: 2009-September-16Security risk: CriticalExploitable from: RemoteVulnerability: Multiple vulnerabilitiesDescriptionMultiple vulnerabilities and weaknesses were discovered in Drupal.OpenID association cross site request forgeriesThe OpenID module in Drupal 6 allows users to create an account or log into a Drupal site using one or more OpenID identities.The core OpenID module does not correctly implement Form API for

More info:

https://www.drupal.org/node/579482