CVE-2008-6532
Last modified
CVE-2008-6532 is a vulnerability of currently unknown severity. Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Drupal | Drupal | 5.0 |
| Drupal | Drupal | 5.1 |
| Drupal | Drupal | 5.2 |
| Drupal | Drupal | 5.3 |
| Drupal | Drupal | 5.4 |
| Drupal | Drupal | 5.5 |
| Drupal | Drupal | 5.6 |
| Drupal | Drupal | 5.7 |
| Drupal | Drupal | 5.8 |
| Drupal | Drupal | 5.9 |
| Drupal | Drupal | 5.10 |
| Drupal | Drupal | 5.11 |
| Drupal | Drupal | 5.12 |
| Drupal | Drupal | 6.0 |
| Drupal | Drupal | 6.1 |
| Drupal | Drupal | 6.2 |
| Drupal | Drupal | 6.3 |
| Drupal | Drupal | 6.4 |
| Drupal | Drupal | 6.5 |
| Drupal | Drupal | 6.6 |
References
- http://drupal.org/node/345441Patch, Vendor Advisory
- http://secunia.com/advisories/33112Vendor Advisory
- http://drupal.org/node/345441Patch, Vendor Advisory
- http://secunia.com/advisories/33112Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-6532?
How severe is CVE-2008-6532?
How do I fix CVE-2008-6532?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-6526SQL injection vulnerability in index.php in BosDev BosClassi…
- CVE-2008-6527SQL injection vulnerability in forum.asp in GO4I.NET ASP For…
- CVE-2008-6528NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers t…
- CVE-2008-6529Cross-site scripting (XSS) vulnerability in listtest.php in …
- CVE-2008-6530Unrestricted file upload vulnerability in editimage.php in e…
- CVE-2008-6531The WebWork 1 web application framework in Atlassian JIRA be…
- CVE-2008-6533Drupal 5.x before 5.13 and 6.x before 6.7 does not delete al…
- CVE-2008-6534Incomplete blacklist vulnerability in NULL FTP Server Free a…
- CVE-2008-6535admin/settings.php in PayPal eStores allows remote attackers…
- CVE-2008-6536Unspecified vulnerability in 7-zip before 4.5.7 has unknown …
- CVE-2008-6537LightNEasy/lightneasy.php in LightNEasy No database version …
- CVE-2008-6538DeStar 0.2.2-5 allows remote attackers to add arbitrary user…
Are you affected by CVE-2008-6532?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
