Drupal Arbitrary PHP Code Execution Vulnerability
BID:14110
Info
Drupal Arbitrary PHP Code Execution Vulnerability
| Bugtraq ID: | 14110 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2106 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Kuba Zygmunt is credited with the discovery of this vulnerability. |
| Vulnerable: |
Drupal Drupal 4.6.1 Drupal Drupal 4.6 Drupal Drupal 4.5.3 Drupal Drupal 4.5.2 Drupal Drupal 4.5.2 Drupal Drupal 4.5.1 Drupal Drupal 4.5 |
| Not Vulnerable: |
Drupal Drupal 4.6.2 Drupal Drupal 4.5.4 |
Discussion
Drupal Arbitrary PHP Code Execution Vulnerability
Drupal is prone to a vulnerability that permits the execution of arbitrary PHP code. This issue is due to a failure in the application to properly sanitize user-supplied input.
The application's filter mechanism fails to properly sanitize user-supplied input to 'comments' and 'postings'.
The vendor has addressed this issue in Drupal versions 4.6.2 and 4.5.4; earlier versions are reported vulnerable.
Drupal is prone to a vulnerability that permits the execution of arbitrary PHP code. This issue is due to a failure in the application to properly sanitize user-supplied input.
The application's filter mechanism fails to properly sanitize user-supplied input to 'comments' and 'postings'.
The vendor has addressed this issue in Drupal versions 4.6.2 and 4.5.4; earlier versions are reported vulnerable.
Exploit / POC
Drupal Arbitrary PHP Code Execution Vulnerability
No exploit is required.
A proof of concept has been provided by dab <[email protected]>.
No exploit is required.
A proof of concept has been provided by dab <[email protected]>.
Solution / Fix
Drupal Arbitrary PHP Code Execution Vulnerability
Solution:
The vendor has addressed this issue in Drupal 4.6.2 and 4.5.4.
Debian Linux has relased security advisory DSA 745-1 addressing this issue for drupal. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Drupal Drupal 4.5
Drupal Drupal 4.5.1
Drupal Drupal 4.5.2
Drupal Drupal 4.5.2
Drupal Drupal 4.5.3
Drupal Drupal 4.6
Drupal Drupal 4.6.1
Solution:
The vendor has addressed this issue in Drupal 4.6.2 and 4.5.4.
Debian Linux has relased security advisory DSA 745-1 addressing this issue for drupal. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Drupal Drupal 4.5
-
Drupal drupal-4.5.5.tar.gz
http://drupal.org/files/projects/drupal-4.5.5.tar.gz
Drupal Drupal 4.5.1
-
Drupal drupal-4.5.5.tar.gz
http://drupal.org/files/projects/drupal-4.5.5.tar.gz
Drupal Drupal 4.5.2
-
Drupal drupal-4.5.5.tar.gz
http://drupal.org/files/projects/drupal-4.5.5.tar.gz
Drupal Drupal 4.5.2
-
Drupal drupal-4.5.5.tar.gz
http://drupal.org/files/projects/drupal-4.5.5.tar.gz
Drupal Drupal 4.5.3
-
Debian drupal_4.5.3-3_all.deb
Debian 3.1 (sarge)
http://security.debian.org/pool/updates/main/d/drupal/drupal_4.5.3-3_a ll.deb -
Drupal drupal-4.5.5.tar.gz
http://drupal.org/files/projects/drupal-4.5.5.tar.gz
Drupal Drupal 4.6
-
Drupal drupal-4.6.2.tar.gz
http://drupal.org/files/projects/drupal-4.6.2.tar.gz
Drupal Drupal 4.6.1
-
Drupal drupal-4.6.2.tar.gz
http://drupal.org/files/projects/drupal-4.6.2.tar.gz
References
Drupal Arbitrary PHP Code Execution Vulnerability
References:
References:
- Drupal 4.6.2 and 4.5.4 released (Drupal)
- Vendor Homepage (Drupal)
- [DRUPAL-SA-2005-002] Drupal 4.6.2 / 4.5.4 fixes input validation issue (Drupal)