Drupal Unspecified Privilege Escalation Vulnerability
BID:13852
Info
Drupal Unspecified Privilege Escalation Vulnerability
| Bugtraq ID: | 13852 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2005 12:00AM |
| Updated: | Jun 03 2005 12:00AM |
| Credit: | The vendor announced this vulnerability. |
| Vulnerable: |
Drupal Drupal 4.6 Drupal Drupal 4.5.2 Drupal Drupal 4.5.1 Drupal Drupal 4.5 Drupal Drupal 4.4.2 Drupal Drupal 4.4.1 Drupal Drupal 4.4 |
| Not Vulnerable: |
Drupal Drupal 4.6.1 Drupal Drupal 4.5.3 Drupal Drupal 4.4.3 |
Discussion
Drupal Unspecified Privilege Escalation Vulnerability
Drupal is prone to an unspecified privilege escalation vulnerability. The issue manifests when public registration is permitted. Using this vulnerability an attacker may gain administrative access to the Drupal installation.
Drupal versions 4.4.0 to 4.6.0 are affected by this vulnerability.
Drupal is prone to an unspecified privilege escalation vulnerability. The issue manifests when public registration is permitted. Using this vulnerability an attacker may gain administrative access to the Drupal installation.
Drupal versions 4.4.0 to 4.6.0 are affected by this vulnerability.
Exploit / POC
Drupal Unspecified Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Drupal Unspecified Privilege Escalation Vulnerability
Solution:
The vendor has released and advisory (DRUPAL-SA-2005-001) and updates to address this issue. Users running Drupal 4.4.x are advised to upgrade to Drupal 4.4.3. Users running Drupal 4.5.2 are advised to upgrade to Drupal 4.5.3. Users running Drupal 4.6.0 Drupal 4.6.1. Please see the referenced advisory for further details.
Solution:
The vendor has released and advisory (DRUPAL-SA-2005-001) and updates to address this issue. Users running Drupal 4.4.x are advised to upgrade to Drupal 4.4.3. Users running Drupal 4.5.2 are advised to upgrade to Drupal 4.5.3. Users running Drupal 4.6.0 Drupal 4.6.1. Please see the referenced advisory for further details.
References
Drupal Unspecified Privilege Escalation Vulnerability
References:
References:
- Vendor Homepage (Drupal)
- DRUPAL-SA-2005-001 - Drupal security advisory (Drupal)