Drupal Menu System Security Bypass Vulnerabilities
BID:28714
Info
Drupal Menu System Security Bypass Vulnerabilities
| Bugtraq ID: | 28714 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-1729 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2008 12:00AM |
| Updated: | May 07 2015 05:30PM |
| Credit: | Peter Wolanin and Greg Knaddison of the Drupal security team |
| Vulnerable: |
Drupal Drupal 6.1 Drupal Drupal 6.0 |
| Not Vulnerable: |
Drupal Drupal 6.2 |
Discussion
Drupal Menu System Security Bypass Vulnerabilities
Drupal is prone to multiple security-bypass vulnerabilities because the application fails to properly control access to some pages. The issues affect the menu system.
Attackers can exploit these issues to bypass certain security restrictions and obtain potentially sensitive information that may lead to other attacks.
The issues affect versions prior to Drupal 6.2.
Drupal is prone to multiple security-bypass vulnerabilities because the application fails to properly control access to some pages. The issues affect the menu system.
Attackers can exploit these issues to bypass certain security restrictions and obtain potentially sensitive information that may lead to other attacks.
The issues affect versions prior to Drupal 6.2.
Exploit / POC
Drupal Menu System Security Bypass Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Drupal Menu System Security Bypass Vulnerabilities
Solution:
The vendor has released updates. Please see the references for more information.
Drupal Drupal 6.1
Drupal Drupal 6.0
Solution:
The vendor has released updates. Please see the references for more information.
Drupal Drupal 6.1
-
Drupal drupal-6.2.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.2.tar.gz
Drupal Drupal 6.0
-
Drupal drupal-6.2.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.2.tar.gz
References
Drupal Menu System Security Bypass Vulnerabilities
References:
References: