Vulnerability Bulletins

SA-2008-073 - Drupal core - Multiple vulnerabilities

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-2008-073Project: Drupal coreVersions: 5.x and 6.xDate: 2008-December-10Security risk: Moderately CriticalExploitable from: RemoteVulnerability: Multiple vulnerabilitiesDescriptionMultiple vulnerabilities and weaknesses were discovered in Drupal.Cross site request forgeryThe update system is vulnerable to Cross site request forgeries. Malicious users may cause the superuser (user 1) to execute old updates that may damage the database.Cross site scriptingWhen an input

More info:

https://www.drupal.org/node/345441