CVE-2009-1576

UnknownEPSS 1.63%

Last modified

CVE-2009-1576 is a vulnerability of currently unknown severity. Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.. EPSS estimates a 1.63% chance of exploitation in the next 30 days.

Description

Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.

Metrics

EPSS Probability
1.63%

73.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersionsUpdate
DrupalDrupal5.0Beta1
DrupalDrupal5.1
DrupalDrupal5.1_rev1.1
DrupalDrupal5.10
DrupalDrupal5.11
DrupalDrupal5.12
DrupalDrupal5.13
DrupalDrupal5.14
DrupalDrupal5.15
DrupalDrupal5.16
DrupalDrupal6.0Beta1
DrupalDrupal6.1
DrupalDrupal6.2
DrupalDrupal6.3
DrupalDrupal6.4
DrupalDrupal6.5
DrupalDrupal6.6
DrupalDrupal6.7
DrupalDrupal6.8
DrupalDrupal6.9
DrupalDrupal6.10

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-1576?
Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.
How severe is CVE-2009-1576?
Severity scoring for CVE-2009-1576 is pending analysis. The EPSS model estimates a 1.63% probability of exploitation in the next 30 days.
How do I fix CVE-2009-1576?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-1576?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST