VDB
CVE-2009-1576
CVE-2009-1576
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.
EPSS 0.80% · 74.4th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
0.80%
74.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| drupal | drupal | 5.1, 5.0, 5.0 |
| n/a | n/a | n/a |
Timeline
- May 6, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- FEDORA-2009-4175 vendor-advisory
- 54153 vdb
- http://www.vbdrupal.org/forum/showthread.php?p=9953#post9953 url
- ADV-2009-1216 vdb
- 34980 third-party-advisory
- http://drupal.org/node/449078 url
- FEDORA-2009-4203 vendor-advisory
- 34950 third-party-advisory
- 34948 third-party-advisory
- DSA-1792 vendor-advisory
- http://drupal.org/files/sa-core-2009-005/SA-CORE-2009-005-5.16.patch url
- https://nvd.nist.gov/vuln/detail/CVE-2009-1576 advisory