Drupal Image Upload HTML Injection Vulnerability
BID:15663
Info
Drupal Image Upload HTML Injection Vulnerability
| Bugtraq ID: | 15663 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3975 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2005 12:00AM |
| Updated: | Feb 07 2006 08:54PM |
| Credit: | The discoverer of this vulnerability is currently unknown, the vendor disclosed this issue. |
| Vulnerable: |
VBulletin VBulletin 3.0.9 VBulletin VBulletin 3.0.8 VBulletin VBulletin 3.0.7 VBulletin VBulletin 3.0.6 VBulletin VBulletin 3.0.5 VBulletin VBulletin 3.0.4 VBulletin VBulletin 3.0.3 VBulletin VBulletin 3.0.2 VBulletin VBulletin 3.0.1 VBulletin VBulletin 3.0 Gamma VBulletin VBulletin 3.0 beta 7 VBulletin VBulletin 3.0 beta 6 VBulletin VBulletin 3.0 beta 5 VBulletin VBulletin 3.0 beta 4 VBulletin VBulletin 3.0 beta 3 VBulletin VBulletin 3.0 beta 2 VBulletin VBulletin 3.0 VBulletin VBulletin 2.3.4 VBulletin VBulletin 2.3.3 VBulletin VBulletin 2.3.2 VBulletin VBulletin 2.3 .0 VBulletin VBulletin 2.2.9 VBulletin VBulletin 2.2.8 VBulletin VBulletin 2.2.7 VBulletin VBulletin 2.2.6 VBulletin VBulletin 2.2.5 VBulletin VBulletin 2.2.4 VBulletin VBulletin 2.2.3 VBulletin VBulletin 2.2.2 VBulletin VBulletin 2.2.1 VBulletin VBulletin 2.2 .0 VBulletin VBulletin 2.0.3 VBulletin VBulletin 2.0 rc 3 VBulletin VBulletin 2.0 rc 2 VBulletin VBulletin 1.0.1 lite Drupal Drupal 4.6.3 Drupal Drupal 4.6.2 Drupal Drupal 4.6.1 Drupal Drupal 4.6 Drupal Drupal 4.5.5 Drupal Drupal 4.5.4 Drupal Drupal 4.5.3 Drupal Drupal 4.5.2 Drupal Drupal 4.5.2 Drupal Drupal 4.5.1 Drupal Drupal 4.5 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
VBulletin VBulletin 3.5.1 VBulletin VBulletin 3.0.10 VBulletin VBulletin 2.3.8 Drupal Drupal 4.6.4 Drupal Drupal 4.5.6 |
Discussion
Drupal Image Upload HTML Injection Vulnerability
Drupal is prone to an HTML-injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
This issue is present only when using Microsoft Internet Explorer.
Drupal is prone to an HTML-injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
This issue is present only when using Microsoft Internet Explorer.
Exploit / POC
Drupal Image Upload HTML Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Drupal Image Upload HTML Injection Vulnerability
Solution:
The vendor has addressed this issue in the latest versions of the affected software. Contact the vendor for the latest updates.
Debian Linux has released security advisory DSA 958-1 addressing this and other issues. Please see the referenced advisory for further information.
Drupal Drupal 4.5
Drupal Drupal 4.5.1
Drupal Drupal 4.5.2
Drupal Drupal 4.5.2
Drupal Drupal 4.5.3
Drupal Drupal 4.5.4
Drupal Drupal 4.5.5
Drupal Drupal 4.6
Drupal Drupal 4.6.1
Drupal Drupal 4.6.2
Drupal Drupal 4.6.3
Solution:
The vendor has addressed this issue in the latest versions of the affected software. Contact the vendor for the latest updates.
Debian Linux has released security advisory DSA 958-1 addressing this and other issues. Please see the referenced advisory for further information.
Drupal Drupal 4.5
-
Drupal drupal-4.5.6.tar.gz
http://drupal.org/files/projects/drupal-4.5.6.tar.gz
Drupal Drupal 4.5.1
-
Drupal drupal-4.5.6.tar.gz
http://drupal.org/files/projects/drupal-4.5.6.tar.gz
Drupal Drupal 4.5.2
-
Drupal drupal-4.5.6.tar.gz
http://drupal.org/files/projects/drupal-4.5.6.tar.gz
Drupal Drupal 4.5.2
-
Drupal drupal-4.5.6.tar.gz
http://drupal.org/files/projects/drupal-4.5.6.tar.gz
Drupal Drupal 4.5.3
-
Drupal drupal-4.5.6.tar.gz
http://drupal.org/files/projects/drupal-4.5.6.tar.gz
Drupal Drupal 4.5.4
-
Drupal drupal-4.5.6.tar.gz
http://drupal.org/files/projects/drupal-4.5.6.tar.gz
Drupal Drupal 4.5.5
-
Drupal drupal-4.5.6.tar.gz
http://drupal.org/files/projects/drupal-4.5.6.tar.gz
Drupal Drupal 4.6
-
Drupal drupal-4.6.4.tar.gz
http://drupal.org/files/projects/drupal-4.6.4.tar.gz
Drupal Drupal 4.6.1
-
Drupal drupal-4.6.4.tar.gz
http://drupal.org/files/projects/drupal-4.6.4.tar.gz
Drupal Drupal 4.6.2
-
Drupal drupal-4.6.4.tar.gz
http://drupal.org/files/projects/drupal-4.6.4.tar.gz
Drupal Drupal 4.6.3
-
Drupal drupal-4.6.4.tar.gz
http://drupal.org/files/projects/drupal-4.6.4.tar.gz
References
Drupal Image Upload HTML Injection Vulnerability
References:
References:
- [DSA 958-1] New drupal packages fix several vulnerabilities (Debian)
- Microsoft Internet Explorer 6.0 Embedded Content Cross Site Scripting (GIF) (securiteam.com)
- vBulletin 3.5.1 Released (vBulletin)
- Vendor Homepage (Kyberna)
- Vendor Homepage (Drupal)
- XSS and HTTP header injection vulnerability with uploaded files (Drupal)