|
|
| |
|
| |
drupal: multiple vulnerabilities
| Package(s): | drupal |
CVE #(s): | CVE-2006-1225
CVE-2006-1226
CVE-2006-1227
CVE-2006-1228
|
| Created: | March 17, 2006 |
Updated: | March 22, 2006 |
| Description: |
The Drupal Security Team discovered several vulnerabilities in Drupal,
a fully-featured content management and discussion engine.
- Due to missing input sanitizing a remote attacker could inject headers
of outgoing e-mail messages and use Drupal as a spam proxy. (CVE-2006-1225)
- Missing input sanity checks allows attackers to inject arbitrary web
script or HTML. (CVE-2006-1226)
- Menu items created with the menu.module lacked access control, which
might allow remote attackers to access administrator pages. (CVE-2006-1227)
- Markus Petrux discovered a bug in the session fixation which may allow
remote attackers to gain Drupal user privileges. (CVE-2006-1228)
|
| Alerts: |
|
( Log in to post comments)
|
|
|