Drupal Multiple HTML Injection Vulnerabilities
BID:28026
Info
Drupal Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 28026 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1131 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2008 12:00AM |
| Updated: | Mar 04 2008 04:12PM |
| Credit: | Steve McKenzie and the Drupal security team discovered these vulnerabilities. |
| Vulnerable: |
Drupal Drupal 6.0 |
| Not Vulnerable: |
Drupal Drupal 6.1 |
Discussion
Drupal Multiple HTML Injection Vulnerabilities
Drupal is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input data.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
These issues affect Drupal 6.0; other versions may also be vulnerable.
Drupal is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input data.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
These issues affect Drupal 6.0; other versions may also be vulnerable.
Exploit / POC
Drupal Multiple HTML Injection Vulnerabilities
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Drupal Multiple HTML Injection Vulnerabilities
Solution:
The vendor released an update to address these issues. Please see the references for more information.
Drupal Drupal 6.0
Solution:
The vendor released an update to address these issues. Please see the references for more information.
Drupal Drupal 6.0
-
Drupal drupal-6.1.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.1.tar.gz
References
Drupal Multiple HTML Injection Vulnerabilities
References:
References:
- Vendor Homepage (Drupal)
- SA-2008-018 - Drupal core - Cross site scripting (Drupal)