CVE-2008-6909
06.08.2009, 18:30
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact, probably related to man-in-the-middle attacks that modify critical data and allow remote attackers to impersonate other users and gain privileges.Enginsight
Vendor | Product | Version |
---|---|---|
marc_ingram | services | 5.x-0.9:x |
marc_ingram | services | 5.x-0.91:x |
marc_ingram | services | 5.x-1.x-dev:x |
marc_ingram | services | 6.x-0.9:x |
marc_ingram | services | 6.x-0.11:x |
marc_ingram | services | 6.x-0.12:x |
marc_ingram | services | 6.x-1.x-dev:x |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References