Drupal Aggregation Module Multiple Vulnerabilities
BID:29677
Info
Drupal Aggregation Module Multiple Vulnerabilities
| Bugtraq ID: | 29677 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-3000 CVE-2008-3001 CVE-2008-2998 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 11 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | fonan, Adam Light and Heine Deelstra |
| Vulnerable: |
Drupal Aggregation 5.x |
| Not Vulnerable: |
Drupal Aggregation 5.x-4.4 |
Discussion
Drupal Aggregation Module Multiple Vulnerabilities
The Aggregation module for Drupal is prone to multiple vulnerabilities, including multiple HTML-injection and SQL-injection vulnerabilities, an arbitrary-file-upload vulnerability, and a security-bypass vulnerability.
An attacker could exploit these vulnerabilities to execute arbitrary script code in the context of the affected site, manipulate SQL query logic, access restricted information, or execute arbitrary code on the server.
These issues affect versions prior to Aggregation 5.x-4.4.
The Aggregation module for Drupal is prone to multiple vulnerabilities, including multiple HTML-injection and SQL-injection vulnerabilities, an arbitrary-file-upload vulnerability, and a security-bypass vulnerability.
An attacker could exploit these vulnerabilities to execute arbitrary script code in the context of the affected site, manipulate SQL query logic, access restricted information, or execute arbitrary code on the server.
These issues affect versions prior to Aggregation 5.x-4.4.
Exploit / POC
Drupal Aggregation Module Multiple Vulnerabilities
An attacker can exploit these issues via a browser.
An attacker can exploit these issues via a browser.
Solution / Fix
Drupal Aggregation Module Multiple Vulnerabilities
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
Drupal Aggregation Module Multiple Vulnerabilities
References:
References:
- Aggregation Homepage (Drupal)
- Drupal Language Switcher Dropdown Homepage (Drupal)
- SA-2008-035 - Aggregation - Multiple vulnerabilities (Drupal)