oval:org.mitre.oval:def:12349
Definition Id: oval:org.mitre.oval:def:12349 | |||
Oval ID: | oval:org.mitre.oval:def:12349 | ||
Title: | DSA-2113-1 drupal6 -- several vulnerabilities | ||
Description: | Several vulnerabilities have been discovered in drupal6 a fully-featured content management framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-3091 Several issues have been discovered in the OpenID module that allows malicious access to user accounts. CVE-2010-3092 The upload module includes a potential bypass of access restrictions due to not checking letter case-sensitivity. CVE-2010-3093 The comment module has a privilege escalation issue that allows certain users to bypass limitations. CVE-2010-3094 Several cross-site scripting issues have been discovered in the Action feature. For the stable distribution, these problems have been fixed in version 6.6-3lenny6. For the testing distribution and the unstable distribution, these problems have been fixed in version 6.18-1. We recommend that you upgrade your drupal6 packages. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2113-1 CVE-2010-3091 CVE-2010-3092 CVE-2010-3093 CVE-2010-3094 | Version: | 5 |
Platform(s): | Debian GNU/Linux 5.0 | Product(s): | drupal6 |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:6513 | |||
Oval ID: | oval:org.mitre.oval:def:6513 | ||
Title: | Debian GNU/Linux 5.0 is installed | ||
Description: | Debian GNU/Linux 5.0 (lenny) is installed | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:debian:debian_gnu/linux:5.0 | Version: | 7 |
Platform(s): | Debian GNU/Linux 5.0 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:12349 |