Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6320 (feature_module)

BugsAlert Home > CVE-2007-6320 (feature_module)
 
 

Feature 4.7.x-dev and 5.x-dev before 20071206, a Drupal module, does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6320

Learn more about CVE-2007-6320 (feature_module)
 
Tags: cve-2007-6320 feature module

Related Items

      ARB Insecure Temporary File Security Issue

      TROJ_ADLOAD.ED

      MS07-030 - Important: Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (927051) - Version:1.1

      JavaScript Code Flow Manipulation

      Orkut/Google Worms Compromise Over 400,000 Accounts

      CVE-2008-3653 (tikiki_cms_groupware)

      FrSIRT - Novell eDirectory LDAP Search Request Heap Corruption Vulnerability

 

Pixel