CVE-2009-1036: CSRF
Published Mar 20, 2009
·Updated
Cross-site request forgery (CSRF) vulnerability in the Plus 1 module before 6.x-2.6, a module for Drupal, allows remote attackers to cast votes for content via unspecified aspects of the URI.
Affected Software
30 affected components
Drupal Plus1<=6.x-2.5
Drupal Plus1=6.x-1.0
Drupal Plus1=6.x-1.1
Drupal Plus1=6.x-1.2
Drupal Plus1=6.x-1.3
Drupal Plus1=6.x-2.0
Drupal Plus1=6.x-2.0-beta2
Drupal Plus1=6.x-2.0-beta3
Drupal Plus1=6.x-2.0-beta4
Drupal Plus1=6.x-2.0-beta5
Drupal Plus1=6.x-2.1
Drupal Plus1=6.x-2.2
Drupal Plus1=6.x-2.3
Drupal Plus1=6.x-2.4
Drupal Drupal
All of the following
Any of the following
Drupal Plus1<=6.x-2.5
Drupal Plus1=6.x-1.0
Drupal Plus1=6.x-1.1
Drupal Plus1=6.x-1.2
Drupal Plus1=6.x-1.3
Drupal Plus1=6.x-2.0
Drupal Plus1=6.x-2.0-beta2
Drupal Plus1=6.x-2.0-beta3
Drupal Plus1=6.x-2.0-beta4
Drupal Plus1=6.x-2.0-beta5
Drupal Plus1=6.x-2.1
Drupal Plus1=6.x-2.2
Drupal Plus1=6.x-2.3
Drupal Plus1=6.x-2.4
Drupal Drupal
Remediation
Patch Available
Event History
Mar 20, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
06:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·06:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-1036?
The severity of CVE-2009-1036 is considered to be moderate due to its potential for Cross-Site Request Forgery attacks.
2
How do I fix CVE-2009-1036?
To fix CVE-2009-1036, upgrade the Plus 1 module to version 6.x-2.6 or later.
3
Which versions of the Plus 1 module are affected by CVE-2009-1036?
Versions of the Plus 1 module prior to 6.x-2.6, including 6.x-2.5 and earlier, are affected by CVE-2009-1036.
4
What type of vulnerability is CVE-2009-1036?
CVE-2009-1036 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2009-1036 be exploited remotely?
Yes, CVE-2009-1036 can be exploited remotely by attackers to cast votes for content.