Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-1576

Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.8%
CVSS Severity
CVSS v2 Score 4.3
References
Products affected by CVE-2009-1576
  • Drupal » Drupal » Version: 5.0
    cpe:2.3:a:drupal:drupal:5.0
  • Drupal » Drupal » Version: 5.1
    cpe:2.3:a:drupal:drupal:5.1
  • Drupal » Drupal » Version: 5.10
    cpe:2.3:a:drupal:drupal:5.10
  • Drupal » Drupal » Version: 5.11
    cpe:2.3:a:drupal:drupal:5.11
  • Drupal » Drupal » Version: 5.12
    cpe:2.3:a:drupal:drupal:5.12
  • Drupal » Drupal » Version: 5.13
    cpe:2.3:a:drupal:drupal:5.13
  • Drupal » Drupal » Version: 5.14
    cpe:2.3:a:drupal:drupal:5.14
  • Drupal » Drupal » Version: 5.15
    cpe:2.3:a:drupal:drupal:5.15
  • Drupal » Drupal » Version: 5.16
    cpe:2.3:a:drupal:drupal:5.16
  • Drupal » Drupal » Version: 5.1_rev1.1
    cpe:2.3:a:drupal:drupal:5.1_rev1.1
  • Drupal » Drupal » Version: 6.0
    cpe:2.3:a:drupal:drupal:6.0
  • Drupal » Drupal » Version: 6.1
    cpe:2.3:a:drupal:drupal:6.1
  • Drupal » Drupal » Version: 6.10
    cpe:2.3:a:drupal:drupal:6.10
  • Drupal » Drupal » Version: 6.2
    cpe:2.3:a:drupal:drupal:6.2
  • Drupal » Drupal » Version: 6.3
    cpe:2.3:a:drupal:drupal:6.3
  • Drupal » Drupal » Version: 6.4
    cpe:2.3:a:drupal:drupal:6.4
  • Drupal » Drupal » Version: 6.5
    cpe:2.3:a:drupal:drupal:6.5
  • Drupal » Drupal » Version: 6.6
    cpe:2.3:a:drupal:drupal:6.6
  • Drupal » Drupal » Version: 6.7
    cpe:2.3:a:drupal:drupal:6.7
  • Drupal » Drupal » Version: 6.8
    cpe:2.3:a:drupal:drupal:6.8
  • Drupal » Drupal » Version: 6.9
    cpe:2.3:a:drupal:drupal:6.9


Contact Us

Shodan ® - All rights reserved