Drupal Plus 1 Module Cross-Site Request Forgery Vulnerability
BID:34168
Info
Drupal Plus 1 Module Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 34168 |
| Class: | Design Error |
| CVE: |
CVE-2009-1036 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2009 12:00AM |
| Updated: | Apr 13 2015 09:11PM |
| Credit: | Greg Knaddison |
| Vulnerable: |
Drupal plus1 0 |
| Not Vulnerable: |
Drupal plus1 6.x-2.6 |
Discussion
Drupal Plus 1 Module Cross-Site Request Forgery Vulnerability
The Plus 1 module for Drupal is prone to a cross-site request-forgery vulnerability.
Attackers may exploit this issue to cause victims to unknowingly vote for attacker-specified content.
Versions prior to Plus 1 6.x-2.6 are vulnerable.
The Plus 1 module for Drupal is prone to a cross-site request-forgery vulnerability.
Attackers may exploit this issue to cause victims to unknowingly vote for attacker-specified content.
Versions prior to Plus 1 6.x-2.6 are vulnerable.
Exploit / POC
Drupal Plus 1 Module Cross-Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Drupal Plus 1 Module Cross-Site Request Forgery Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for details.
Solution:
Vendor updates are available. Please contact the vendor for details.
References
Drupal Plus 1 Module Cross-Site Request Forgery Vulnerability
References:
References:
- Plus 1 Homepage (Drupal)
- plus1 6.x-2.6 security update (Drupal)