CVE

Id
80626  
CVE No.
CVE-2015-3349  
Status
Candidate  
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the Htaccess module before 7.x-2.3 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) deploy or (2) delete an .htaccess file via unspecified vectors.  
Phase
Assigned (20150421)  
Votes
None (candidate not yet proposed)  
Comments