Drupal Project and Project Issues Tracking Modules Multiple Vulnerabilities
BID:22224
Info
Drupal Project and Project Issues Tracking Modules Multiple Vulnerabilities
| Bugtraq ID: | 22224 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0506 CVE-2007-0505 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 25 2007 12:00AM |
| Updated: | Jul 06 2016 02:40PM |
| Credit: | Brandon Bergren, Derek Wright, and Heine Deelstra are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Drupal Project issue tracking 4.7.0-2.1 Drupal Project issue tracking 4.7.0-1.1 Drupal Project 4.6 Drupal Project 4.7.0-2.1 Drupal Project 4.7.0-1.1 Drupal Project 4.7.0 Drupal Project 4.6.0-1.1 |
| Not Vulnerable: |
Drupal Project issue tracking 4.7 2.2 Drupal Project issue tracking 4.7 1.2 Drupal Project 5.0 1-beta Drupal Project 4.7 2-2 Drupal Project 4.7 1.2 |
Discussion
Drupal Project and Project Issues Tracking Modules Multiple Vulnerabilities
Drupal Project and Project Issues Tracking modules are prone to an unauthorized-access vulnerability, cross-site scripting vulnerability, and arbitrary code-execution vulnerability.
A remote attacker can navigate to scripts that have administrative access and can view, modify, and delete application data, steal cookie-based authentication credentials, and compromise the application.
Drupal Project and Project Issues Tracking modules are prone to an unauthorized-access vulnerability, cross-site scripting vulnerability, and arbitrary code-execution vulnerability.
A remote attacker can navigate to scripts that have administrative access and can view, modify, and delete application data, steal cookie-based authentication credentials, and compromise the application.
Exploit / POC
Drupal Project and Project Issues Tracking Modules Multiple Vulnerabilities
An attacker can exploit these issues via a web client. To exploit a cross-site scripting vulnerability, the attacker must entice a victim user to follow a malicious URI.
An attacker can exploit these issues via a web client. To exploit a cross-site scripting vulnerability, the attacker must entice a victim user to follow a malicious URI.
Solution / Fix
Drupal Project and Project Issues Tracking Modules Multiple Vulnerabilities
Solution:
The vendor has released updates to address these issues.
Drupal Project 4.6.0-1.1
Drupal Project issue tracking 4.7.0-1.1
Drupal Project 4.7.0
Drupal Project 4.7.0-2.1
Drupal Project issue tracking 4.7.0-2.1
Drupal Project 4.7.0-1.1
Drupal Project 4.6
Solution:
The vendor has released updates to address these issues.
Drupal Project 4.6.0-1.1
-
Drupal project-4.7.x-1.2.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/project-4.7.x-1.2.tar. gz -
Drupal project-5.x-0.1-beta.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/project-5.x-0.1-beta.t ar.gz
Drupal Project issue tracking 4.7.0-1.1
-
Drupal project_issue-4.7.x-1.2.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/project_issue-4.7.x-1. 2.tar.gz -
Drupal project_issue-5.x-0.1-beta.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/project_issue-5.x-0.1- beta.tar.gz
Drupal Project 4.7.0
-
Drupal project-4.7.x-1.2.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/project-4.7.x-1.2.tar. gz -
Drupal project-5.x-0.1-beta.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/project-5.x-0.1-beta.t ar.gz
Drupal Project 4.7.0-2.1
-
Drupal project-4.7.x-2.2.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/project-4.7.x-2.2.tar. gz -
Drupal project-5.x-0.1-beta.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/project-5.x-0.1-beta.t ar.gz
Drupal Project issue tracking 4.7.0-2.1
-
Drupal project_issue-4.7.x-2.2.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/project_issue-4.7.x-2. 2.tar.gz -
Drupal project_issue-5.x-0.1-beta.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/project_issue-5.x-0.1- beta.tar.gz
Drupal Project 4.7.0-1.1
-
Drupal project-4.7.x-1.2.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/project-4.7.x-1.2.tar. gz -
Drupal project-5.x-0.1-beta.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/project-5.x-0.1-beta.t ar.gz
Drupal Project 4.6
-
Drupal project-4.7.x-1.2.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/project-4.7.x-1.2.tar. gz -
Drupal project-5.x-0.1-beta.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/project-5.x-0.1-beta.t ar.gz
References
Drupal Project and Project Issues Tracking Modules Multiple Vulnerabilities
References:
References:
- Drupal Security Advisory DRUPAL-SA-2007-004 (Drupal)
- Vendor Homepage (Drupal)