Drupal CMS 7.12 (latest stable release) Multiple Vulnerabilities
Drupal 7.12 -latest stable release - suffers from multiple vulnerabilities which could allow an attacker to gain administrative access to the CMS. The first vulnerability is a CSRF which could allow an attacker to change any Drupal settings. The second vulnerability is a CSRF which could allow an attacker to force administrator logout. The third vulnerability is a POST and GET method which could allow an attacker to gain administrative access to the CMS. The fourth vulnerability is a Http Referer which could allow an attacker to gain administrative access to the CMS. The exploit is a POST and GET method which could allow an attacker to gain administrative access to the CMS. The exploit is a CSRF which could allow an attacker to force administrator logout.