|
|
| |
|
| |
drupal: multiple vulnerabilities
| Package(s): | drupal6 |
CVE #(s): | CVE-2010-3091
CVE-2010-3092
CVE-2010-3093
CVE-2010-3094
|
| Created: | September 20, 2010 |
Updated: | September 22, 2010 |
| Description: |
From the Debian advisory:
Several issues have been discovered in the OpenID module that allows
malicious access to user accounts. (CVE-2010-3091)
The upload module includes a potential bypass of access restrictions due
to not checking letter case-sensitivity. (CVE-2010-3092)
The comment module has a privilege escalation issue that allows certain
users to bypass limitations. (CVE-2010-3093)
Several cross-site scripting (XSS) issues have been discovered in the
Action feature. (CVE-2010-3094)
|
| Alerts: |
|
( Log in to post comments)
|
|
|