Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Drupal 6.x < 6.37 Multiple Vulnerabilities

Medium

Synopsis

The remote server is hosting an outdated installation of Drupal that is vulnerable to multiple attack vectors.

Description

The remote server is hosting an outdated version of Drupal, a PHP-based open-source content management system. The version of Drupal installed on the remote server is 6.x prior to 6.37, and is affected by the following vulnerabilities :

- A cross-site scripting (XSS) vulnerability exists in the autocomplete functionality due to improper validation of input passed via requested URLs. An authenticated, remote attacker can exploit this, via a specially crafted request, to execute arbitrary script code. (CVE-2015-6658) - A cross-site request forgery (CSRF) vulnerability exists in the form API due to improper validation of form tokens. An authenticated, remote attacker can exploit this, via a specially crafted link, to upload arbitrary files under another user's account. (CVE-2015-6660) - An information disclosure vulnerability exists that allows a remote, authenticated user to view the titles of nodes that they do not have access to. (CVE-2015-6661)

Solution

Upgrade to Drupal 6.37, or later.