提醒:SA-CORE-2012-001 - Drupal core multiple vulnerabilities 2012年02月02日

订阅:buren
演示:以MSN订阅提醒为例 订阅到哪吒,有更新提醒我
哪吒机器人提醒:
提醒:Security advisories
【标题】SA-CORE-2012-001 - Drupal core multiple vulnerabilities
【摘要】advisory id: drupal-sa-core-2012-001project: drupal coreversion: 6.x, 7.xdate: 2012-february-01security risk: moderately criticalexploitable from: remotevulnerability: access bypass, cross site request forgery, multiple vulnerabilitiesdescriptioncross site request forgery vulnerability in aggregator modulecve: cve-2012-0826an xsrf vulnerability can force an aggregator feed to update. since some services are rate-limited (e.g. twitter limits requests to 150 per hour) this could lead to ... (02-02 14:11)
收藏 |  评论 |  推荐给好友  | 
本文共有 0 次分享
评论
共有 - 条评论


我要反馈