CVE-2008-6532

Drupal 5.x < 5.13 and 6.x < 6.7 - Cross-Site Request Forgery in Update Feature

Title source: llm
STIX 2.1

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.

References (8)

Core 8
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3414
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33147
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33112
Patch, Vendor Advisory x_refsource_confirm
http://drupal.org/node/345441
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/50661
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47260

Scores

EPSS 0.0033
EPSS Percentile 55.9%

Details

CWE
CWE-352
Status published
Products (20)
drupal/drupal 5.0
drupal/drupal 5.1
drupal/drupal 5.2
drupal/drupal 5.3
drupal/drupal 5.4
drupal/drupal 5.5
drupal/drupal 5.6
drupal/drupal 5.7
drupal/drupal 5.8
drupal/drupal 5.9
... and 10 more
Published Mar 26, 2009
Tracked Since Feb 18, 2026