FreeBSD : drupal -- multiple vulnerabilities (609c790e-ce0a-11dd-a721-0030843d3802)

Medium Nessus Plugin ID 35242


The remote FreeBSD host is missing one or more security-related updates.


The Drupal Project reports :

The update system is vulnerable to Cross site request forgeries.
Malicious users may cause the superuser (user 1) to execute old updates that may damage the database.

When an input format is deleted, not all existing content on a site is updated to reflect this deletion. Such content is then displayed unfiltered. This may lead to cross site scripting attacks when harmful tags are no longer stripped from 'malicious' content that was posted earlier.


Update the affected packages.

See Also

Plugin Details

Severity: Medium

ID: 35242

File Name: freebsd_pkg_609c790ece0a11dda7210030843d3802.nasl

Version: $Revision: 1.12 $

Type: local

Published: 2008/12/21

Modified: 2013/06/21

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:drupal5, p-cpe:/a:freebsd:freebsd:drupal6, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2008/12/19

Vulnerability Publication Date: 2008/12/11

Reference Information

CVE: CVE-2008-6533

Secunia: 33112

CWE: 79