First published: Sun Apr 22 2007(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remote attackers to perform unauthorized actions as an arbitrary user, a related issue to CVE-2006-5476.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Database Administration Module | =4.6 | |
Drupal Database Administration Module | =4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2160 is a high severity vulnerability due to its potential for unauthorized actions by remote attackers.
To fix CVE-2007-2160, update the Database Administration module to version 4.7.x-1.2 or later.
CVE-2007-2160 allows attackers to perform unauthorized actions via cross-site request forgery (CSRF).
CVE-2007-2160 affects Drupal Database Administration module versions 4.6.x-* and 4.7.x-1.* before 4.7.x-1.2.
Users of the affected versions of the Database Administration module in Drupal could be impacted as their accounts may be exploited.