CVE-2008-3743

Publication date 27 August 2008

Last updated 24 July 2024


Ubuntu priority

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions via unknown vectors, related to improper token validation for (1) cached forms and (2) forms with AHAH elements.

Read the notes from the security team

Status

Package Ubuntu Release Status
drupal5 8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
7.04 feisty Not in release
6.06 LTS dapper Not in release
drupal 8.04 LTS hardy Not in release
7.10 gutsy Not in release
7.04 feisty
Not affected
6.06 LTS dapper
Not affected

Notes


jdstrand

per Debian, vulnerable code not present


Access our resources on patching vulnerabilities