Drupal Webform Multiple Unspecified Cross-Site Scripting Vulnerabilities
BID:18947
CVE-2006-3570 |Info
Drupal Webform Multiple Unspecified Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 18947 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2006 12:00AM |
| Updated: | Jul 13 2006 07:23PM |
| Credit: | Heine Deelstra is credited with the discovery of this vulnerability. |
| Vulnerable: |
Drupal Drupal webform 4.7 Drupal Drupal webform 4.6 |
| Not Vulnerable: | |
Discussion
Drupal Webform Multiple Unspecified Cross-Site Scripting Vulnerabilities
Drupal is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions 4.6 and 4.7 (released prior to July 8, 2006) of webform are affected by these issues.
Drupal is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions 4.6 and 4.7 (released prior to July 8, 2006) of webform are affected by these issues.
Exploit / POC
Drupal Webform Multiple Unspecified Cross-Site Scripting Vulnerabilities
An attacker can exploit these issues by tricking a victim user into following a malicious URI.
An attacker can exploit these issues by tricking a victim user into following a malicious URI.
Solution / Fix
Drupal Webform Multiple Unspecified Cross-Site Scripting Vulnerabilities
Solution:
The vendor has released upgrades to address these issues. The latest versions available from the vendor's site are not affected.
Solution:
The vendor has released upgrades to address these issues. The latest versions available from the vendor's site are not affected.
References
Drupal Webform Multiple Unspecified Cross-Site Scripting Vulnerabilities
References:
References:
- Easylinks multiple vulnerabilities (Drupal)