ZeroHour

CVE-2016-3163

CVSS 3.0
7.5 high
EPSS
1%p71
Published
()
Modified
Description

The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.

Vendors
debiandrupal
Products
debian linux, drupal
Ecosystems
Drupal
Weakness
CWE-254
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.