CVE-2009-2374
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.
Drupal v.5.x anteriores a v.5.19 y 6.x anteriores a v.6.13 no limpian adecuadamente el intento de acceso fallido a páginas que contienen tablas ordenadas,que incluyen el nombre de usuario y contraseña que puede ser leidas desde (1) la cabecera referida a HTTP de sitios web externos que son visitados desde estos enlaces o (2) cuando la página es activado, la pagina cache Drupal.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-07-08 CVE Reserved
- 2009-07-08 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-255: Credentials Management Errors
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/35657 | Third Party Advisory | |
http://secunia.com/advisories/35681 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://drupal.org/node/507572 | 2021-04-21 | |
http://osvdb.org/55524 | 2021-04-21 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | >= 5.0 < 5.19 Search vendor "Drupal" for product "Drupal" and version " >= 5.0 < 5.19" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | >= 6.0 < 6.13 Search vendor "Drupal" for product "Drupal" and version " >= 6.0 < 6.13" | - |
Affected
|