CVE-2006-5477
Drupal 4.6.x-4.6.9 and 4.7.x-4.7.3 - Unauthenticated Form Information Disclosure via Redirect
Title source: llmDescription
Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows form submissions to be redirected, which allows remote attackers to obtain arbitrary form information via a crafted URL.
References (8)
Core 8
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/449200/100/0/threaded
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/20631
Vendor Advisory vendor-advisory
x_refsource_openpkg
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.025-drupal.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/29682
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22486
Patch, Vendor Advisory x_refsource_confirm
http://drupal.org/node/88828
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/1764
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4120
Scores
EPSS
0.0068
EPSS Percentile
71.9%
Details
Status
published
Products (14)
drupal/drupal
4.6.0
drupal/drupal
4.6.1
drupal/drupal
4.6.2
drupal/drupal
4.6.3
drupal/drupal
4.6.4
drupal/drupal
4.6.5
drupal/drupal
4.6.6
drupal/drupal
4.6.7
drupal/drupal
4.6.8
drupal/drupal
4.6.9
... and 4 more
Published
Oct 24, 2006
Tracked Since
Feb 18, 2026