Drupal User.Module Cross-Site Scripting Vulnerability
BID:19325
CVE-2006-4002 |Info
Drupal User.Module Cross-Site Scripting Vulnerability
| Bugtraq ID: | 19325 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4002 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2006 12:00AM |
| Updated: | Mar 08 2007 03:35AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Drupal Drupal 4.7.2 Drupal Drupal 4.7.1 Drupal Drupal 4.7 Drupal Drupal 4.6.8 Drupal Drupal 4.6.7 Drupal Drupal 4.6.6 Drupal Drupal 4.6.5 Drupal Drupal 4.6.4 Drupal Drupal 4.6.3 Drupal Drupal 4.6.2 Drupal Drupal 4.6.1 Drupal Drupal 4.6 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Drupal Drupal 4.7.3 Drupal Drupal 4.6.9 |
Discussion
Drupal User.Module Cross-Site Scripting Vulnerability
Drupal is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Drupal 4.6x and 4.7x are affected by this issue.
Drupal is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Drupal 4.6x and 4.7x are affected by this issue.
Exploit / POC
Drupal User.Module Cross-Site Scripting Vulnerability
An attacker can exploit this issue by tricking a victim user into following a malicious URI.
An attacker can exploit this issue by tricking a victim user into following a malicious URI.
Solution / Fix
Drupal User.Module Cross-Site Scripting Vulnerability
Solution:
The vendor has released upgrades to address these issues. The latest versions available from the vendor's site are not affected.
Please see the referenced advisories for more information.
Solution:
The vendor has released upgrades to address these issues. The latest versions available from the vendor's site are not affected.
Please see the referenced advisories for more information.