Release date:
Updated on: 2012-10-03
Affected Systems:
Drupal Password Policy 6. X-1.X
Unaffected system:
Drupal Password Policy 6. X-1.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51385
Cve id: CVE-2012-1633
Drupal is an open-source CMS that can be used as a content management platform for various websites.
Drupal Password Policy Module 6. A cross-site scripting vulnerability in the x-1.x. Attackers can hijack administrator users to access user request verification.
<* Source: Greg Knaddison
Link: http://secunia.com/advisories/47541
Http://www.openwall.com/lists/oss-security/2012/04/07/1
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Drupal
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://drupal.org/