Drupal Submitted Content HTML Injection Vulnerability
BID:15677
Info
Drupal Submitted Content HTML Injection Vulnerability
| Bugtraq ID: | 15677 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3973 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2005 12:00AM |
| Updated: | Feb 07 2006 08:54PM |
| Credit: | Ahmed Saad is credited with the discovery of this vulnerability. |
| Vulnerable: |
Drupal Drupal 4.6.3 Drupal Drupal 4.6.2 Drupal Drupal 4.6.1 Drupal Drupal 4.6 Drupal Drupal 4.5.5 Drupal Drupal 4.5.4 Drupal Drupal 4.5.3 Drupal Drupal 4.5.2 Drupal Drupal 4.5.2 Drupal Drupal 4.5.1 Drupal Drupal 4.5 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Drupal Drupal 4.6.4 Drupal Drupal 4.5.6 |
Discussion
Drupal Submitted Content HTML Injection Vulnerability
Drupal is prone to an HTML-injection vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
Drupal is prone to an HTML-injection vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
Exploit / POC
Drupal Submitted Content HTML Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Drupal Submitted Content HTML Injection Vulnerability
Solution:
Debian Linux has released security advisory DSA 958-1 addressing this and other issues. Please see the referenced advisory for further information.
The vendor has released updates addressing this issue:
Drupal Drupal 4.5
Drupal Drupal 4.5.1
Drupal Drupal 4.5.2
Drupal Drupal 4.5.2
Drupal Drupal 4.5.3
Drupal Drupal 4.5.4
Drupal Drupal 4.5.5
Drupal Drupal 4.6
Drupal Drupal 4.6.1
Drupal Drupal 4.6.2
Drupal Drupal 4.6.3
Solution:
Debian Linux has released security advisory DSA 958-1 addressing this and other issues. Please see the referenced advisory for further information.
The vendor has released updates addressing this issue:
Drupal Drupal 4.5
-
Drupal drupal-4.5.6.tar.gz
http://drupal.org/files/projects/drupal-4.5.6.tar.gz
Drupal Drupal 4.5.1
-
Drupal drupal-4.5.6.tar.gz
http://drupal.org/files/projects/drupal-4.5.6.tar.gz
Drupal Drupal 4.5.2
-
Drupal drupal-4.5.6.tar.gz
http://drupal.org/files/projects/drupal-4.5.6.tar.gz
Drupal Drupal 4.5.2
-
Drupal drupal-4.5.6.tar.gz
http://drupal.org/files/projects/drupal-4.5.6.tar.gz
Drupal Drupal 4.5.3
-
Drupal drupal-4.5.6.tar.gz
http://drupal.org/files/projects/drupal-4.5.6.tar.gz
Drupal Drupal 4.5.4
-
Drupal drupal-4.5.6.tar.gz
http://drupal.org/files/projects/drupal-4.5.6.tar.gz
Drupal Drupal 4.5.5
-
Drupal drupal-4.5.6.tar.gz
http://drupal.org/files/projects/drupal-4.5.6.tar.gz
Drupal Drupal 4.6
-
Drupal drupal-4.6.4.tar.gz
http://drupal.org/files/projects/drupal-4.6.4.tar.gz
Drupal Drupal 4.6.1
-
Drupal drupal-4.6.4.tar.gz
http://drupal.org/files/projects/drupal-4.6.4.tar.gz
Drupal Drupal 4.6.2
-
Drupal drupal-4.6.4.tar.gz
http://drupal.org/files/projects/drupal-4.6.4.tar.gz
Drupal Drupal 4.6.3
-
Drupal drupal-4.6.4.tar.gz
http://drupal.org/files/projects/drupal-4.6.4.tar.gz
References
Drupal Submitted Content HTML Injection Vulnerability
References:
References: