CVE-2008-6910
06.08.2009, 18:30
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers to impersonate other users and gain privileges via a replay attack that sends the same request.Enginsight
Vendor | Product | Version |
---|---|---|
marc_ingram | services | 5.x-0.9:x |
marc_ingram | services | 5.x-0.91:x |
marc_ingram | services | 5.x-1.x-dev:x |
marc_ingram | services | 6.x-0.9:x |
marc_ingram | services | 6.x-0.11:x |
marc_ingram | services | 6.x-0.12:x |
marc_ingram | services | 6.x-1.x-dev:x |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References