Vulnerabilities > CVE-2007-4063 - Cross-Site Request Forgery vulnerability in Drupal
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE network
drupal
Summary
Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.2 allow remote attackers to (1) delete comments, (2) delete content revisions, and (3) disable menu items as privileged users, related to improper use of HTTP GET and the Forms API.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |