← Back

CVE-2008-6532

nvd nist
Published: Mar 26, 2009Modified: Apr 23, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.

Affected (20)

Products: Drupal: Drupal
1 product
Drupal
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Drupal
Version 5.0
Version 5.10
Version 5.11
Version 5.12
Version 5.1
Version 5.2
Version 5.3
Version 5.4
Version 5.5
Version 5.6
Version 5.7
Version 5.8
Version 5.9
Version 6.0
Version 6.1
Version 6.2
Version 6.3
Version 6.4
Version 6.5
Version 6.6

References (16)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.