Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.808042
Kategorie:Web application abuses
Titel:Drupal Multiple Vulnerabilities01- May16 (Windows)
Zusammenfassung:This host is running Drupal and is prone; to multiple vulnerabilities.
Beschreibung:Summary:
This host is running Drupal and is prone
to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws exixts due to:

- An error in session data truncation which can lead to unserialization of
user provided data

- The 'drupal_goto' function improperly decodes the contents of
'$_REQUEST['destination']' before using it.

- Form API ignores access restrictions on submit buttons.

- An error in the 'drupal_set_header' function.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to cause remote code execution, initiate a redirect to an arbitrary
external URL, bypass security restrictions and inject arbitrary HTTP
headers.

Affected Software/OS:
Drupal 6.x before 6.38 on Windows.

Solution:
Upgrade to version 6.38 or later.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-3171
Debian Security Information: DSA-3498 (Google Search)
http://www.debian.org/security/2016/dsa-3498
http://www.openwall.com/lists/oss-security/2016/02/24/19
http://www.openwall.com/lists/oss-security/2016/03/15/10
Common Vulnerability Exposure (CVE) ID: CVE-2016-3167
Common Vulnerability Exposure (CVE) ID: CVE-2016-3165
Common Vulnerability Exposure (CVE) ID: CVE-2016-3166
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.