漏洞信息详情
Drupal跨站请求伪造漏洞
漏洞简介
Drupal是一个开放源码的网站内容管理系统(CMS)平台。
Drupal 5.13版本之前的5.x版本以及6.7版本之前的6.x版本的更新特性中存在多个跨站请求伪造漏洞。远程攻击者可以借助未明向量,仿效超级用户执行未认证操作,例如造成超级用户Atlassian JIRA 3.13.2版本之前的版本的WebWork 1版本网络应用程序框架允许远程攻击者可以借助一个特制定并不断地转化为方法调用的URL,又称\"WebWork 1版本参数注入缺口\",以激活无掩护的大众JIRA方法路径\"执行旧的更新信息\"更改数据库。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Drupal
Drupal 6.1
Drupal drupal-6.7.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.7.tar.gz
Drupal 5.10
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal 5.12
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 5.8
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 5.1 revision 1.1
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 5.11
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 5.5
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 5.2
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 5.7
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 6.5
Drupal drupal-6.7.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.7.tar.gz
Drupal Drupal 6.3
Drupal drupal-6.7.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.7.tar.gz
Drupal Drupal 6.0
Drupal drupal-6.7.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.7.tar.gz
Drupal Drupal 5.3
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 6.2
Drupal drupal-6.7.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.7.tar.gz
Drupal Drupal 5.9
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal 5.1
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal 6.6
Drupal drupal-6.7.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.7.tar.gz
Drupal 5.0
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal 5.6
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal 6.4
Drupal drupal-6.7.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.7.tar.gz
Drupal 5.4
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
参考网址
来源: drupal.org
链接:http://drupal.org/node/345441
来源: FEDORA
名称: FEDORA-2008-11213
链接: https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00767.html
来源: FEDORA
名称: FEDORA-2008-11196
链接: https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00740.html
来源: XF
名称: drupal-unspecified-superuser-csrf(47260)
链接: http://xforce.iss.net/xforce/xfdb/47260
来源: VUPEN
名称: ADV-2008-3414
链接: http://www.vupen.com/english/advisories/2008/3414
来源: OSVDB
名称: 50661
链接: http://www.osvdb.org/50661
来源: SECUNIA
名称: 33147
链接: http://secunia.com/advisories/33147
来源: SECUNIA
名称: 33112
链接: http://secunia.com/advisories/33112
受影响实体
- Drupal Drupal:6.1<!--2000-1-1-->
- Drupal Drupal:6.2<!--2000-1-1-->
- Drupal Drupal:6.3<!--2000-1-1-->
- Drupal Drupal:6.4<!--2000-1-1-->
- Drupal Drupal:6.5<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...