Drupal Header image Module Authentication Bypass Vulnerability
BID:27787
Info
Drupal Header image Module Authentication Bypass Vulnerability
| Bugtraq ID: | 27787 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-0823 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Erik Stielstra reported this issue. |
| Vulnerable: |
Drupal Header image 5.x-1.0 |
| Not Vulnerable: |
Drupal Header image 5.x-1.1 |
Discussion
Drupal Header image Module Authentication Bypass Vulnerability
The Header image module for Drupal is prone to an authentication-bypass vulnerability due to an unspecified error.
An attacker can exploit this issue to gain unauthorized access to the module's administration pages. This may lead to further attacks.
This issue affects versions prior to Header image 5.x-1.1 for Drupal 5.x. Note that Drupal Core without this module is not affected by this issue.
The Header image module for Drupal is prone to an authentication-bypass vulnerability due to an unspecified error.
An attacker can exploit this issue to gain unauthorized access to the module's administration pages. This may lead to further attacks.
This issue affects versions prior to Header image 5.x-1.1 for Drupal 5.x. Note that Drupal Core without this module is not affected by this issue.
Exploit / POC
Drupal Header image Module Authentication Bypass Vulnerability
An attacker will likely use a browser to exploit this issue.
An attacker will likely use a browser to exploit this issue.
Solution / Fix
Drupal Header image Module Authentication Bypass Vulnerability
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Drupal Header image 5.x-1.0
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Drupal Header image 5.x-1.0
-
Drupal headerimage-5.x-1.1.tar.gz
http://ftp.drupal.org/files/projects/headerimage-5.x-1.1.tar.gz
References
Drupal Header image Module Authentication Bypass Vulnerability
References:
References:
- Header image Homepage (Drupal)
- Vendor Homepage (Drupal)
- DRUPAL-SA-2008-017 - Header image - Access bypass (Drupal)