oval:org.mitre.oval:def:13542
Definition Id: oval:org.mitre.oval:def:13542 | |||
Oval ID: | oval:org.mitre.oval:def:13542 | ||
Title: | DSA-1792-1 drupal6 -- multiple | ||
Description: | Multiple vulnerabilities have been discovered in drupal, a web content management system. pod.Edge discovered a cross-site scripting vulnerability due that can be triggered when some browsers interpret UTF-8 strings as UTF-7 if they appear before the generated HTML document defines its Content-Type. This allows a malicious user to execute arbitrary javascript in the context of the web site if they’re allowed to post content. Moritz Naumann discovered an information disclosure vulnerability. If a user is tricked into visiting the site via a specially crafted URL and then submits a form from that page, the information in their form submission may be directed to a third-party site determined by the URL and thus disclosed to the third party. The third party site may then execute a cross-site request forgery attack against the submitted form. For the stable distribution, these problems have been fixed in version 6.6-3lenny1. The old stable distribution does not contain drupal and is not affected. For the unstable distribution, these problems have been fixed in version 6.11-1 We recommend that you upgrade your drupal6 package. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1792-1 CVE-2009-1575 CVE-2009-1576 | Version: | 5 |
Platform(s): | Debian GNU/Linux 5.0 | Product(s): | drupal6 |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:6513 | |||
Oval ID: | oval:org.mitre.oval:def:6513 | ||
Title: | Debian GNU/Linux 5.0 is installed | ||
Description: | Debian GNU/Linux 5.0 (lenny) is installed | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:debian:debian_gnu/linux:5.0 | Version: | 7 |
Platform(s): | Debian GNU/Linux 5.0 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:13542 |