Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers to impersonate other users and gain privileges via a replay attack that sends the same request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Marc_Ingram Drupal Services模块重放攻击漏洞
Vulnerability Description
Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。 Drupal的Services 模块发送请求时签名超时,远程攻击者可以通过发送同样的请求信息的重放攻击,模拟用户获取权限。
CVSS Information
N/A
Vulnerability Type
N/A