CVE-2016-3168
published 2016-04-12CVE-2016-3168: The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests…
PriorityP432medium6.4CVSS 3.0
AVNACHPRHUIRSUCHIHAH
EPSS
2.48%
82.6th percentile
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."
Affected
87 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| drupal | core | >= 6.0 < 6.38 | 6.38 |
| drupal | core | >= 7.0 < 7.43 | 7.43 |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
CVSS provenance
nvdv3.06.4MEDIUMCVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
osv6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Drupal Reflected file download vulnerability
ghsa·2022-05-17
CVE-2016-3168 [MEDIUM] Drupal Reflected file download vulnerability
Drupal Reflected file download vulnerability
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."
OSV
Drupal Reflected file download vulnerability
osv·2022-05-17
CVE-2016-3168 [MEDIUM] Drupal Reflected file download vulnerability
Drupal Reflected file download vulnerability
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."
OSV
CVE-2016-3168: The System module in Drupal 6
osv·2016-04-12·CVSS 6.4
CVE-2016-3168 [MEDIUM] CVE-2016-3168: The System module in Drupal 6
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."
No detection rules found.
No public exploits indexed.
http://www.debian.org/security/2016/dsa-3498http://www.openwall.com/lists/oss-security/2016/02/24/19http://www.openwall.com/lists/oss-security/2016/03/15/10https://www.drupal.org/SA-CORE-2016-001http://www.debian.org/security/2016/dsa-3498http://www.openwall.com/lists/oss-security/2016/02/24/19http://www.openwall.com/lists/oss-security/2016/03/15/10https://www.drupal.org/SA-CORE-2016-001
2016-04-12
Published