CVE Vulnerabilities

CVE-2007-4063

Published: Jul 30, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.2 allow remote attackers to (1) delete comments, (2) delete content revisions, and (3) disable menu items as privileged users, related to improper use of HTTP GET and the Forms API.

Affected Software

NameVendorStart VersionEnd Version
DrupalDrupal5.0 (including)5.0 (including)
DrupalDrupal5.1 (including)5.1 (including)
DrupalDrupal5.1_rev1.1 (including)5.1_rev1.1 (including)
DrupalUbuntufeisty*

References