CVE-2009-4066
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) subscribing or (2) unsubscribing to mailing lists.
Múltiples vulnerabilidades de falsificación de petición en sitios cruzados(CSRF) en el apartado "My Account" (mi cuenta) del módulo PHPList Integration v5 anteriores a v5.x-1.2 y v6 anteriores a v6.x-1.1 de Drupal. Permiten a atacantes remotos secuestrar las credenciales de autenticación de usuarios de su elección a través de vectores de ataque relacionados con (1) la suscripción (2) o desinscripción de las listas de correo.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-11-23 CVE Reserved
- 2009-11-24 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://osvdb.org/60283 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/54336 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://drupal.org/node/636398 | 2017-08-17 | |
http://drupal.org/node/636400 | 2017-08-17 | |
http://drupal.org/node/636412 | 2017-08-17 | |
http://www.securityfocus.com/bid/37054 | 2017-08-17 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/37434 | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Affected
| in | Paul Beaney Search vendor "Paul Beaney" | Phplist Search vendor "Paul Beaney" for product "Phplist" | 5.x-1.0 Search vendor "Paul Beaney" for product "Phplist" and version "5.x-1.0" | - |
Affected
|
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Affected
| in | Paul Beaney Search vendor "Paul Beaney" | Phplist Search vendor "Paul Beaney" for product "Phplist" | 5.x-1.1 Search vendor "Paul Beaney" for product "Phplist" and version "5.x-1.1" | - |
Affected
|
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Affected
| in | Paul Beaney Search vendor "Paul Beaney" | Phplist Search vendor "Paul Beaney" for product "Phplist" | 5.x-1.x Search vendor "Paul Beaney" for product "Phplist" and version "5.x-1.x" | dev |
Affected
|
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Affected
| in | Paul Beaney Search vendor "Paul Beaney" | Phplist Search vendor "Paul Beaney" for product "Phplist" | 6.x-1.0 Search vendor "Paul Beaney" for product "Phplist" and version "6.x-1.0" | - |
Affected
|
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Affected
| in | Paul Beaney Search vendor "Paul Beaney" | Phplist Search vendor "Paul Beaney" for product "Phplist" | 6.x-1.x Search vendor "Paul Beaney" for product "Phplist" and version "6.x-1.x" | dev |
Affected
|