CVE Database
/

CVE-2009-1576

Back to search

CVE-2009-1576

Published: May 6, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2009-4175
vendor-advisory
x_refsource_FEDORA
54153
vdb-entry
x_refsource_OSVDB
ADV-2009-1216
vdb-entry
x_refsource_VUPEN
34980
third-party-advisory
x_refsource_SECUNIA
FEDORA-2009-4203
vendor-advisory
x_refsource_FEDORA
34950
third-party-advisory
x_refsource_SECUNIA
34948
third-party-advisory
x_refsource_SECUNIA
DSA-1792
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now