First published: Tue Feb 05 2008(Updated: )
Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attackers to gain the privileges of a user who has authenticated from behind the same proxy server as the attacker.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Secure Site Module | =4.7 | |
Drupal Secure Site Module | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0568 is considered a high severity vulnerability due to the potential for remote attackers to gain unauthorized privileges.
To fix CVE-2008-0568, upgrade to a patched version of the Secure Site module for Drupal that addresses this vulnerability.
CVE-2008-0568 affects Drupal Secure Site module versions 4.7.x-1.0 and 5.x-1.0.
Yes, an attacker can exploit CVE-2008-0568 remotely if they are behind the same proxy server as an authenticated user.
The impact of CVE-2008-0568 allows attackers to gain privileges of users who authenticated through the same proxy server, compromising user account security.