Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-5594
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-5594

Description:
Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/37268

SAID
  Secunia Advisory: SA27290
  Secunia Advisory: SA27352

FEDORA

CONFIRM
  http://drupal.org/node/184348

BID
  26119


Return to the previous page.