Drupal forms contains a token to protect against cross site request forgeries (CSRF). The token may not been validated properly for cached forms and forms containing AHAH elements.
Part of security release SA-2008-047
This vulnerability affects the following application versions:
- Drupal 6.0
- Drupal 6.1
- Drupal 6.2
- Drupal 6.3