Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
2013-10-28T22:55:03.383
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | drupal | drupal | 6.0 | Yes |
Application | drupal | drupal | 6.0 | Yes |
Application | drupal | drupal | 6.0 | Yes |
Application | drupal | drupal | 6.0 | Yes |
Application | drupal | drupal | 6.0 | Yes |
Application | drupal | drupal | 6.0 | Yes |
Application | drupal | drupal | 6.0 | Yes |
Application | drupal | drupal | 6.0 | Yes |
Application | drupal | drupal | 6.0 | Yes |
Application | drupal | drupal | 6.0 | Yes |
Application | drupal | drupal | 6.1 | Yes |
Application | drupal | drupal | 6.2 | Yes |
Application | drupal | drupal | 6.10 | Yes |
Application | drupal | drupal | 6.11 | Yes |
Application | drupal | drupal | 6.12 | Yes |
Application | drupal | drupal | 6.13 | Yes |
Application | drupal | drupal | 6.14 | Yes |
Application | drupal | drupal | 6.15 | Yes |
Application | drupal | drupal | 6.16 | Yes |
Application | drupal | drupal | 6.17 | Yes |
Application | drupal | drupal | 6.18 | Yes |
Application | drupal | drupal | 6.19 | Yes |
Application | drupal | drupal | 6.20 | Yes |
Application | drupal | drupal | 6.21 | Yes |
Application | drupal | drupal | 6.22 | Yes |
Application | drupal | drupal | 6.23 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.0 | Yes |
Application | drupal | drupal | 7.1 | Yes |
Application | drupal | drupal | 7.2 | Yes |
Application | drupal | drupal | 7.3 | Yes |
Application | drupal | drupal | 7.4 | Yes |
Application | drupal | drupal | 7.5 | Yes |
Application | drupal | drupal | 7.6 | Yes |
Application | drupal | drupal | 7.7 | Yes |
Application | drupal | drupal | 7.8 | Yes |
Application | drupal | drupal | 7.9 | Yes |
Application | drupal | drupal | 7.10 | Yes |
Application | drupal | drupal | 7.x | Yes |
Application | drupal | drupal | 7.x-dev | Yes |