The update system was vulnerable to cross site request forgeries. Malicious users may cause the superuser to execute old updates that may damage the database.
Part of security release SA-2008-073
This vulnerability affects the following application versions:
- Drupal 6.0
- Drupal 6.1
- Drupal 6.2
- Drupal 6.3
- Drupal 6.4
- Drupal 6.5
- Drupal 6.6