CVE-2008-6532
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.
Vulnerabilidad múltiple de falsificación de petición en sitios cruzados - CSRF - en la característica de actualización en Drupal v5.x anteriores a v5.13 y v6.x anteriores a v6.7, permiten a los atacantes remotos desarrollar acciones no autorizadas como el superusuarío a través de vectores no especificados, como se ha demostrado por provocación del superusuario la "ejecución de antiguas actualizaciones" que modifican la base de datos.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-03-26 CVE Reserved
- 2009-03-26 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/33147 | Third Party Advisory | |
http://www.osvdb.org/50661 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/3414 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/47260 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://drupal.org/node/345441 | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 5.0 Search vendor "Drupal" for product "Drupal" and version "5.0" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 5.1 Search vendor "Drupal" for product "Drupal" and version "5.1" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 5.2 Search vendor "Drupal" for product "Drupal" and version "5.2" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 5.3 Search vendor "Drupal" for product "Drupal" and version "5.3" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 5.4 Search vendor "Drupal" for product "Drupal" and version "5.4" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 5.5 Search vendor "Drupal" for product "Drupal" and version "5.5" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 5.6 Search vendor "Drupal" for product "Drupal" and version "5.6" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 5.7 Search vendor "Drupal" for product "Drupal" and version "5.7" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 5.8 Search vendor "Drupal" for product "Drupal" and version "5.8" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 5.9 Search vendor "Drupal" for product "Drupal" and version "5.9" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 5.10 Search vendor "Drupal" for product "Drupal" and version "5.10" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 5.11 Search vendor "Drupal" for product "Drupal" and version "5.11" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 5.12 Search vendor "Drupal" for product "Drupal" and version "5.12" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 6.0 Search vendor "Drupal" for product "Drupal" and version "6.0" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 6.1 Search vendor "Drupal" for product "Drupal" and version "6.1" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 6.2 Search vendor "Drupal" for product "Drupal" and version "6.2" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 6.3 Search vendor "Drupal" for product "Drupal" and version "6.3" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 6.4 Search vendor "Drupal" for product "Drupal" and version "6.4" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 6.5 Search vendor "Drupal" for product "Drupal" and version "6.5" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 6.6 Search vendor "Drupal" for product "Drupal" and version "6.6" | - |
Affected
|