Summary
Christian Mainka and Vladislav Mladenov reported a vulnerability in the OpenID module of Drupal, a fully-featured content management framework.
A malicious user could exploit this flaw to log in as other users on the site, including administrators, and hijack their accounts.
These fixes require extra updates to the database which can be done from the administration pages.
Solution
For the oldstable distribution (squeeze), this problem has been fixed in version 6.30-1.
We recommend that you upgrade your drupal6 packages.
Insight
Drupal is a dynamic web site platform which allows an individual or community of users to publish, manage and organize a variety of content, Drupal integrates many popular features of content management systems, weblogs, collaborative tools and discussion-based community software into one easy-to-use package.
Affected
drupal6 on Debian Linux
Detection
This check tests the installed software version using the apt package manager.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2014-1475 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities