Drupal Unspecified Cross-Site Scripting Vulnerability
BID:21887
Info
Drupal Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 21887 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2007 12:00AM |
| Updated: | Jan 08 2007 05:06PM |
| Credit: | An anonymous researcher is credited with discovering this issue. |
| Vulnerable: |
OpenPKG OpenPKG Stable OpenPKG OpenPKG E1.0-Solid OpenPKG OpenPKG Current OpenPKG OpenPKG 2-Stable-20061018 Drupal Drupal 4.7.4 Drupal Drupal 4.7.3 Drupal Drupal 4.7.3 Drupal Drupal 4.7.2 Drupal Drupal 4.7.1 Drupal Drupal 4.7 Drupal Drupal 4.6.10 Drupal Drupal 4.6.9 Drupal Drupal 4.6.8 Drupal Drupal 4.6.7 Drupal Drupal 4.6.6 Drupal Drupal 4.6.5 Drupal Drupal 4.6.4 Drupal Drupal 4.6.3 Drupal Drupal 4.6.2 Drupal Drupal 4.6.1 Drupal Drupal 4.6 Drupal Drupal 4.7 revision 1.15 Drupal Drupal 4.7 |
| Not Vulnerable: |
Drupal Drupal 4.7.5 Drupal Drupal 4.6.11 |
Discussion
Drupal Unspecified Cross-Site Scripting Vulnerability
Drupal is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Drupal 4.6 and 4.7 series are affected by this issue.
Drupal is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Drupal 4.6 and 4.7 series are affected by this issue.
Exploit / POC
Drupal Unspecified Cross-Site Scripting Vulnerability
An attacker can exploit this issue by tricking a victim user into following a malicious URI.
An attacker can exploit this issue by tricking a victim user into following a malicious URI.
Solution / Fix
Drupal Unspecified Cross-Site Scripting Vulnerability
Solution:
The vendor has released upgrades to address these issues.
Please see the referenced advisories for more information.
Drupal Drupal 4.7
Drupal Drupal 4.6
Drupal Drupal 4.6.1
Drupal Drupal 4.6.10
Drupal Drupal 4.6.2
Drupal Drupal 4.6.3
Drupal Drupal 4.6.4
Drupal Drupal 4.6.5
Drupal Drupal 4.6.6
Drupal Drupal 4.6.7
Drupal Drupal 4.6.8
Drupal Drupal 4.6.9
Drupal Drupal 4.7
Drupal Drupal 4.7.1
Drupal Drupal 4.7.2
Drupal Drupal 4.7.3
Drupal Drupal 4.7.3
Drupal Drupal 4.7.4
Solution:
The vendor has released upgrades to address these issues.
Please see the referenced advisories for more information.
Drupal Drupal 4.7
-
Drupal drupal-4.7.5.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.7.5.tar.gz
Drupal Drupal 4.6
-
Drupal drupal-4.6.11.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.6.11.tar.gz
Drupal Drupal 4.6.1
-
Drupal drupal-4.6.11.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.6.11.tar.gz
Drupal Drupal 4.6.10
-
Drupal drupal-4.6.11.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.6.11.tar.gz
Drupal Drupal 4.6.2
-
Drupal drupal-4.6.11.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.6.11.tar.gz
Drupal Drupal 4.6.3
-
Drupal drupal-4.6.11.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.6.11.tar.gz
Drupal Drupal 4.6.4
-
Drupal drupal-4.6.11.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.6.11.tar.gz
Drupal Drupal 4.6.5
-
Drupal drupal-4.6.11.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.6.11.tar.gz
Drupal Drupal 4.6.6
-
Drupal drupal-4.6.11.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.6.11.tar.gz
Drupal Drupal 4.6.7
-
Drupal drupal-4.6.11.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.6.11.tar.gz
Drupal Drupal 4.6.8
-
Drupal drupal-4.6.11.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.6.11.tar.gz
Drupal Drupal 4.6.9
-
Drupal drupal-4.6.11.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.6.11.tar.gz
Drupal Drupal 4.7
-
Drupal drupal-4.7.5.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.7.5.tar.gz
Drupal Drupal 4.7.1
-
Drupal drupal-4.7.5.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.7.5.tar.gz
Drupal Drupal 4.7.2
-
Drupal drupal-4.7.5.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.7.5.tar.gz
Drupal Drupal 4.7.3
-
Drupal drupal-4.7.5.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.7.5.tar.gz
Drupal Drupal 4.7.3
-
Drupal drupal-4.7.5.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.7.5.tar.gz
Drupal Drupal 4.7.4
-
Drupal drupal-4.7.5.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.7.5.tar.gz