Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable all Views or (2) disable all Views.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2010/12/16/7 | Patch |
http://drupal.org/node/829840 | Patch Vendor Advisory |
http://www.openwall.com/lists/oss-security/2010/12/22/1 | Patch |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Information
Published : 2010-12-23 10:00
Updated : 2010-12-26 21:00
NVD link : CVE-2010-4519
Mitre link : CVE-2010-4519
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
drupal
- drupal
earl_miles
- views