LWN.net Logo

drupal: cross site request forgery

Package(s):drupal CVE #(s):
Created:July 27, 2007 Updated:August 1, 2007
Description: From DRUPAL-SA-2007-017: "Several parts in Drupal core are not protected against cross site request forgeries due to inproper use of the Forms API, or by taking action solely on GET requests. Malicious users are able to delete comments and content revisions and disable menu items by enticing a privileged users to visit certain URLs while the victim is logged-in to the targeted site."
Alerts:
Fedora FEDORA-2007-1295 2007-07-26

(Log in to post comments)

drupal: cross site request forgery

Posted Aug 12, 2007 12:24 UTC (Sun) by kreutzm (guest, #4700) [Link]

Debian is not affected: The version in Sarge is too old and Etch does not ship drupal.

drupal: cross site request forgery

Posted Oct 12, 2007 16:27 UTC (Fri) by iDownload (guest, #48358) [Link]

Install mod_security apache module, setup correct rules and forget about it! As i plan to do on my collection of software files.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds