CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2009-1576

MEDIUM
4.3
CVSS Severity Score
EPSS Score0.1700%
EPSS Percentile16.24th
Published2009年5月6日
Last Modified2026年4月23日

Vulnerability Description

Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.

Affected Platforms (CPE)

📦
Drupal

Drupal

= 5.0
📦
Drupal

Drupal

= 5.0
📦
Drupal

Drupal

= 5.0
📦
Drupal

Drupal

= 5.0
📦
Drupal

Drupal

= 5.1
📦
Drupal

Drupal

= 5.1_rev1.1
📦
Drupal

Drupal

= 5.10
📦
Drupal

Drupal

= 5.11
📦
Drupal

Drupal

= 5.12
📦
Drupal

Drupal

= 5.13
📦
Drupal

Drupal

= 5.14
📦
Drupal

Drupal

= 5.15
📦
Drupal

Drupal

= 5.16
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.1
📦
Drupal

Drupal

= 6.2
📦
Drupal

Drupal

= 6.3
📦
Drupal

Drupal

= 6.4
📦
Drupal

Drupal

= 6.5
📦
Drupal

Drupal

= 6.6
📦
Drupal

Drupal

= 6.7
📦
Drupal

Drupal

= 6.8
📦
Drupal

Drupal

= 6.9
📦
Drupal

Drupal

= 6.10

References & Advisories

相關漏洞威脅