HTTP: Dries Buytaert Drupal Core OpenID Module Information Disclosure
This signature detects attempts to exploit a known flaw in Drupal Core. A successful attack can lead to unauthorized information disclosure.
Extended Description
The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.
Affected Products
Drupal drupal
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Drupal
5.0