|
|
Database Administration for Drupal Cross Site Scripting and Request Forgery Issues
|
Multiple vulnerabilities have been identified in Database Administration (module for Drupal), which could be exploited by attackers to execute arbitrary scripting code or bypass security checks.
The first issue is caused by input validation errors in the administrative and user interfaces, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
The second issue is caused by errors in various scripts that do not validate HTTP GET and POST requests, which could be exploited by malicious people to conduct cross site request forgery attacks.
Database Administration (module for Drupal) versions prior to 4.7.x-1.2
Upgrade to version 4.7.x-1.2 :
http://drupal.org/node/135552
http://www.vupen.com/english/advisories/2007/1360 http://drupal.org/node/135549
Vulnerabilities reported by Derek Wright and Heine Deelstra.
2007-04-12 : Initial release
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|