Drupal TrailScout Module SQL Injection And HTML Injection Vulnerabilities
BID:29807
Info
Drupal TrailScout Module SQL Injection And HTML Injection Vulnerabilities
| Bugtraq ID: | 29807 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2849 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 18 2008 12:00AM |
| Updated: | Apr 16 2015 05:59PM |
| Credit: | Gerhard Killesreiter |
| Vulnerable: |
TrailScout TrailScout 5.x-1.3 |
| Not Vulnerable: |
TrailScout TrailScout 5.x-1.4 |
Discussion
Drupal TrailScout Module SQL Injection And HTML Injection Vulnerabilities
The TrailScout module for Drupal is prone to multiple input-validation vulnerabilities, including an SQL-injection issue and an HTML-injection issue.
Attackers can exploit these issues to steal cookie-based authentication credentials from legitimate users of the site, modify the way the site is rendered, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to TrailScout 5.x-1.4 are affected.
The TrailScout module for Drupal is prone to multiple input-validation vulnerabilities, including an SQL-injection issue and an HTML-injection issue.
Attackers can exploit these issues to steal cookie-based authentication credentials from legitimate users of the site, modify the way the site is rendered, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to TrailScout 5.x-1.4 are affected.
Exploit / POC
Drupal TrailScout Module SQL Injection And HTML Injection Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
Drupal TrailScout Module SQL Injection And HTML Injection Vulnerabilities
Solution:
The vendor released an update to address these issues. Please see the references for more information.
Solution:
The vendor released an update to address these issues. Please see the references for more information.
References
Drupal TrailScout Module SQL Injection And HTML Injection Vulnerabilities
References:
References:
- TrailScout Homepage (TrailScout)
- SA-2008-037 - TrailScout - XSS and SQL injection (Drupal)