CVE-2008-3220

NameCVE-2008-3220
DescriptionCross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs490559

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
drupal-4.7source(unstable)(not affected)
drupal5source(unstable)5.8-1low490559

Notes

- drupal-4.7 <not-affected> (Vulnerable code not present)
drupal-4.7 uses the locale_admin_string_delete callback which returns a confirmation dialog

Search for package or bug name: Reporting problems