LWN.net Logo

drupal: multiple vulnerabilities

Package(s):drupal CVE #(s):CVE-2006-1225 CVE-2006-1226 CVE-2006-1227 CVE-2006-1228
Created:March 17, 2006 Updated:March 22, 2006
Description: The Drupal Security Team discovered several vulnerabilities in Drupal, a fully-featured content management and discussion engine.
  • Due to missing input sanitizing a remote attacker could inject headers of outgoing e-mail messages and use Drupal as a spam proxy. (CVE-2006-1225)
  • Missing input sanity checks allows attackers to inject arbitrary web script or HTML. (CVE-2006-1226)
  • Menu items created with the menu.module lacked access control, which might allow remote attackers to access administrator pages. (CVE-2006-1227)
  • Markus Petrux discovered a bug in the session fixation which may allow remote attackers to gain Drupal user privileges. (CVE-2006-1228)
Alerts:
Debian DSA-1007-1 2006-03-17

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds