In association with heise online

11 July 2008, 14:33

Security update for Drupal CMS

The developers of the Drupal CMS have released versions 5.8 and 6.3, which close cross-site scripting, cross-request forgery, and SQL injection holes. In particular, the OpenID module contains XSS vulnerabilities that attackers could exploit to steal login data. Users who cannot upgrade to the new versions are advised to install the patches for Drupal 5.7 or 6.2.

See also:

(trk)

  • Share this article
  • Twitter
  • Facebook
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit






The H open source

The H Security

The H Internet Toolkit