CVE-2009-1576 is an unspecified vulnerability affecting Drupal 5.x before 5.17 and 6.x before 6.11. It allows user-assisted remote attackers to obtain sensitive information by manipulating crafted URLs, potentially leading to form data being sent to an attacker-controlled site. This vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity, requiring user interaction, and resulting in partial confidentiality impact. While it can be leveraged for Cross-Site Request Forgery (CSRF) attacks, there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:5.0:beta1:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:5.0:beta2:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:5.0:rc1:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:5.0:rc2:*:*:*:*:*:* | ||
5.1CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.