LWN.net Logo

drupal: multiple vulnerabilities

Package(s):drupal6 CVE #(s):CVE-2010-3091 CVE-2010-3092 CVE-2010-3093 CVE-2010-3094
Created:September 20, 2010 Updated:September 22, 2010
Description: From the Debian advisory:

Several issues have been discovered in the OpenID module that allows malicious access to user accounts. (CVE-2010-3091)

The upload module includes a potential bypass of access restrictions due to not checking letter case-sensitivity. (CVE-2010-3092)

The comment module has a privilege escalation issue that allows certain users to bypass limitations. (CVE-2010-3093)

Several cross-site scripting (XSS) issues have been discovered in the Action feature. (CVE-2010-3094)

Alerts:
Debian DSA-2113-1 2010-09-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds