Lucene search

K
cve[email protected]CVE-2008-6169
HistoryFeb 19, 2009 - 3:30 p.m.

CVE-2008-6169

2009-02-1915:30:00
CWE-352
web.nvd.nist.gov
18
cve-2008-6169
cross-site request forgery
csrf
localization client
localization server
drupal
unauthorized actions
administrators

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.5%

Cross-site request forgery (CSRF) vulnerability in the Localization client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization server 5.x before 5.x-1.0-alpha5 and 6.x before 6.x-alpha2, modules for Drupal, allows remote attackers to perform unauthorized actions as administrators via unspecified vectors related to the “local translation submission interface.”

Affected configurations

NVD
Node
drupallocalization_clientRange5.x-1.0
OR
drupallocalization_clientRange6.x-1.5
OR
drupallocalization_clientMatch5.x-1.xdev
OR
drupallocalization_clientMatch6.x-1.0
OR
drupallocalization_clientMatch6.x-1.1
OR
drupallocalization_clientMatch6.x-1.2
OR
drupallocalization_clientMatch6.x-1.3
OR
drupallocalization_clientMatch6.x-1.4
OR
drupallocalization_clientMatch6.x-1.xdev
OR
drupallocalization_serverRange5.x-1.0alpha4
OR
drupallocalization_serverRange6.x-1.0alpha1
OR
drupallocalization_serverMatch5.x-1.0alpha1
OR
drupallocalization_serverMatch5.x-1.0alpha2
OR
drupallocalization_serverMatch5.x-1.0alpha3
OR
drupallocalization_serverMatch5.x-1.xdev
OR
drupallocalization_serverMatch6.x-1.xdev

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.5%

Related for CVE-2008-6169