FreeBSD : drupal -- multiple vulnerabilities (609c790e-ce0a-11dd-a721-0030843d3802)

medium Nessus Plugin ID 35242

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

The Drupal Project reports :

The update system is vulnerable to Cross site request forgeries.
Malicious users may cause the superuser (user 1) to execute old updates that may damage the database.

When an input format is deleted, not all existing content on a site is updated to reflect this deletion. Such content is then displayed unfiltered. This may lead to cross site scripting attacks when harmful tags are no longer stripped from 'malicious' content that was posted earlier.

Solution

Update the affected packages.

See Also

http://drupal.org/node/345441

http://www.nessus.org/u?716de3dd

Plugin Details

Severity: Medium

ID: 35242

File Name: freebsd_pkg_609c790ece0a11dda7210030843d3802.nasl

Version: 1.15

Type: local

Published: 12/21/2008

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:drupal6, cpe:/o:freebsd:freebsd, p-cpe:/a:freebsd:freebsd:drupal5

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 12/19/2008

Vulnerability Publication Date: 12/11/2008

Reference Information

CVE: CVE-2008-6533

CWE: 79

Secunia: 33112