CyberSec.Space Logo
Back to CVE Browser

CVE-2009-1576

MEDIUM
4.3
CVSS Severity Score
EPSS Score0.1700%
EPSS Percentile16.24th
PublishedMay 6, 2009
Last ModifiedApr 23, 2026

Vulnerability Description

Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.

Affected Platforms (CPE)

πŸ“¦
Drupal

Drupal

= 5.0
πŸ“¦
Drupal

Drupal

= 5.0
πŸ“¦
Drupal

Drupal

= 5.0
πŸ“¦
Drupal

Drupal

= 5.0
πŸ“¦
Drupal

Drupal

= 5.1
πŸ“¦
Drupal

Drupal

= 5.1_rev1.1
πŸ“¦
Drupal

Drupal

= 5.10
πŸ“¦
Drupal

Drupal

= 5.11
πŸ“¦
Drupal

Drupal

= 5.12
πŸ“¦
Drupal

Drupal

= 5.13
πŸ“¦
Drupal

Drupal

= 5.14
πŸ“¦
Drupal

Drupal

= 5.15
πŸ“¦
Drupal

Drupal

= 5.16
πŸ“¦
Drupal

Drupal

= 6.0
πŸ“¦
Drupal

Drupal

= 6.0
πŸ“¦
Drupal

Drupal

= 6.0
πŸ“¦
Drupal

Drupal

= 6.0
πŸ“¦
Drupal

Drupal

= 6.0
πŸ“¦
Drupal

Drupal

= 6.0
πŸ“¦
Drupal

Drupal

= 6.0
πŸ“¦
Drupal

Drupal

= 6.0
πŸ“¦
Drupal

Drupal

= 6.1
πŸ“¦
Drupal

Drupal

= 6.2
πŸ“¦
Drupal

Drupal

= 6.3
πŸ“¦
Drupal

Drupal

= 6.4
πŸ“¦
Drupal

Drupal

= 6.5
πŸ“¦
Drupal

Drupal

= 6.6
πŸ“¦
Drupal

Drupal

= 6.7
πŸ“¦
Drupal

Drupal

= 6.8
πŸ“¦
Drupal

Drupal

= 6.9
πŸ“¦
Drupal

Drupal

= 6.10

References & Advisories

Related Vulnerabilities