Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-2374 | First vendor Publication | 2009-07-08 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2374 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-255 | Credentials Management |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:13660 | |||
Oval ID: | oval:org.mitre.oval:def:13660 | ||
Title: | DSA-1930-1 drupal6 -- several vulnerabilities | ||
Description: | Several vulnerabilities have been found in drupal6, a fully-featured content management framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-2372 Gerhard Killesreiter discovered a flaw in the way user signatures are handled. It is possible for a user to inject arbitrary code via a crafted user signature. CVE-2009-2373 Mark Piper, Sven Herrmann and Brandon Knight discovered a cross-site scripting issue in the forum module, which could be exploited via the tid parameter. CVE-2009-2374 Sumit Datta discovered that certain drupal6 pages leak sensible information such as user credentials. Several design flaws in the OpenID module have been fixed, which could lead to cross-site request forgeries or privilege escalations. Also, the file upload function does not process all extensions properly leading to the possible execution of arbitrary code. For the stable distribution, these problems have been fixed in version 6.6-3lenny3. The oldstable distribution does not contain drupal6. For the testing distribution and the unstable distribution, these problems have been fixed in version 6.14-1. We recommend that you upgrade your drupal6 packages. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1930-1 CVE-2009-2372 CVE-2009-2373 CVE-2009-2374 | Version: | 5 |
Platform(s): | Debian GNU/Linux 5.0 | Product(s): | drupal6 |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:7333 | |||
Oval ID: | oval:org.mitre.oval:def:7333 | ||
Title: | DSA-1930 drupal6 -- several vulnerabilities | ||
Description: | Several vulnerabilities have been found in drupal6, a fully-featured content management framework. The Common Vulnerabilities and Exposures project identifies the following problems: Gerhard Killesreiter discovered a flaw in the way user signatures are handled. It is possible for a user to inject arbitrary code via a crafted user signature. (SA-CORE-2009-007) Mark Piper, Sven Herrmann and Brandon Knight discovered a cross-site scripting issue in the forum module, which could be exploited via the tid parameter. (SA-CORE-2009-007) Sumit Datta discovered that certain drupal6 pages leak sensitive information such as user credentials. (SA-CORE-2009-007) Several design flaws in the OpenID module have been fixed, which could lead to cross-site request forgeries or privilege escalations. Also, the file upload function does not process all extensions properly leading to the possible execution of arbitrary code. (SA-CORE-2009-008) The oldstable distribution (etch) does not contain drupal6. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1930 CVE-2009-2372 CVE-2009-2373 CVE-2009-2374 | Version: | 3 |
Platform(s): | Debian GNU/Linux 5.0 | Product(s): | drupal6 |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2009-11-11 | Name : Debian Security Advisory DSA 1930-1 (drupal6) File : nvt/deb_1930_1.nasl |
2009-07-15 | Name : FreeBSD Ports: drupal5 File : nvt/freebsd_drupal513.nasl |
2009-07-15 | Name : Drupal Information Disclosure Vulnerability File : nvt/gb_drupal_info_disclosure_vuln.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
55524 | Drupal Core Forum Module Unspecified XSS Drupal Core Forum Module contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecified parameter(s) upon submission to unspecified script(s). This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-02-24 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1930.nasl - Type : ACT_GATHER_INFO |
2009-07-14 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_be9272986f9711deb444001372fd0af2.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 23:10:54 |
|
2024-11-28 12:19:22 |
|
2021-05-04 12:10:10 |
|
2021-04-22 00:22:46 |
|
2019-05-10 12:02:56 |
|
2018-10-18 12:02:35 |
|
2016-06-28 17:45:31 |
|
2016-04-26 18:57:22 |
|
2014-02-17 10:50:41 |
|
2013-05-10 23:53:40 |
|