Vulnerability Description
Unspecified vulnerability in Boost before 6.x-1.03, a module for Drupal, allows remote attackers to create new webroot directories via unknown attack vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 316Solutions | Boost | <= 6.x-1.01 |
| Drupal | Drupal | All versions |
References
- http://drupal.org/node/592470Patch
- http://drupal.org/node/592490PatchVendor Advisory
- http://osvdb.org/58424
- http://secunia.com/advisories/36925Vendor Advisory
- http://www.securityfocus.com/bid/36561
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53553
- http://drupal.org/node/592470Patch
- http://drupal.org/node/592490PatchVendor Advisory
- http://osvdb.org/58424
- http://secunia.com/advisories/36925Vendor Advisory
- http://www.securityfocus.com/bid/36561
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53553
FAQ
What is CVE-2009-3654?
CVE-2009-3654 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Unspecified vulnerability in Boost before 6.x-1.03, a module for Drupal, allows remote attackers to create new webroot directories via unknown attack vectors.
How severe is CVE-2009-3654?
CVE-2009-3654 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-3654?
Check the references section above for vendor advisories and patch information. Affected products include: 316Solutions Boost, Drupal Drupal.