Vulnerability Name: | CVE-2009-2374 (CCN-51503) | ||||||||||||||||
Assigned: | 2009-07-01 | ||||||||||||||||
Published: | 2009-07-01 | ||||||||||||||||
Updated: | 2021-04-21 | ||||||||||||||||
Summary: | Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-255 | ||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2009-2374 Source: CCN Type: DRUPAL-SA-CORE-2009-007 SA-CORE-2009-007 - Drupal core - Multiple vulnerabilities Source: CONFIRM Type: Patch, Vendor Advisory http://drupal.org/node/507572 Source: OSVDB Type: Broken Link, Patch 55524 Source: CCN Type: SA35657 Drupal URL Information Disclosure Security Issue Source: SECUNIA Type: Third Party Advisory 35657 Source: CCN Type: SA35681 Drupal Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory 35681 Source: CCN Type: SA35704 vbDrupal URL Information Disclosure Security Issue Source: CCN Type: SourceForge.net: Files vbDrupal, File Release Notes and Changelog, Release Name: 5.19.0 Source: DEBIAN Type: DSA-1930 drupal6 -- several vulnerabilities Source: CCN Type: OSVDB ID: 55524 Drupal Core Forum Module Unspecified XSS Source: CCN Type: OSVDB ID: 55526 Drupal Core Login Failure HTTP Referer Header Password Disclosure Source: CCN Type: BID-35548 Drupal Cross-Site Scripting, Code Injection and Information Disclosure Vulnerabilities Source: XF Type: UNKNOWN drupal-url-information-disclosure(51503) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |