Drupal Mailhandler Module Multiple SQL Injection Vulnerabilities
BID:31230
Info
Drupal Mailhandler Module Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 31230 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4148 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2008 12:00AM |
| Updated: | May 07 2015 05:23PM |
| Credit: | Zohar Stolar |
| Vulnerable: |
Drupal Mailhandler Module 6.x-1.3 Drupal Mailhandler Module 5.x-1.3 |
| Not Vulnerable: |
Drupal Mailhandler Module 6.x-1.4 Drupal Mailhandler Module 5.x-1.4 |
Discussion
Drupal Mailhandler Module Multiple SQL Injection Vulnerabilities
The Mailhandler module for Drupal is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in SQL queries.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect versions prior to Mailhandler 5.x-1.4 and prior to 6.x-1.4.
The Mailhandler module for Drupal is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in SQL queries.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect versions prior to Mailhandler 5.x-1.4 and prior to 6.x-1.4.
Exploit / POC
Drupal Mailhandler Module Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Drupal Mailhandler Module Multiple SQL Injection Vulnerabilities
Solution:
Fixes are available. Please see the references for more information.
Drupal Mailhandler Module 6.x-1.3
Drupal Mailhandler Module 5.x-1.3
Solution:
Fixes are available. Please see the references for more information.
Drupal Mailhandler Module 6.x-1.3
-
Drupal Mailhandler 6.x-1.4
http://drupal.org/node/309770
Drupal Mailhandler Module 5.x-1.3
-
Drupal Mailhandler 5.x-1.4
http://drupal.org/node/309771
References
Drupal Mailhandler Module Multiple SQL Injection Vulnerabilities
References:
References:
- Mailhandler Homepage (Drupal)
- SA-2008-050 - Mailhandler - SQL injection (Drupal)