Drupal Stock 'stock quote' Page Authentication Bypass Vulnerability
BID:31389
Info
Drupal Stock 'stock quote' Page Authentication Bypass Vulnerability
| Bugtraq ID: | 31389 |
| Class: | Design Error |
| CVE: |
CVE-2008-4710 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2008 12:00AM |
| Updated: | May 07 2015 05:23PM |
| Credit: | Greg Knaddison (greggles) |
| Vulnerable: |
Drupal Stock 6.x-1.x-dev |
| Not Vulnerable: |
Drupal Stock 6.x-1.0 |
Discussion
Drupal Stock 'stock quote' Page Authentication Bypass Vulnerability
The Stock module for Drupal is prone to an authentication-bypass vulnerability.
Attackers can exploit this issue to gain unauthorized access to certain portions of the affected application. Successfully exploiting this issue may allow attackers to execute arbitrary script code within the context of the web browser and steal cookie-based authentication credentials.
http://drupal.org/node/207891
The Stock module for Drupal is prone to an authentication-bypass vulnerability.
Attackers can exploit this issue to gain unauthorized access to certain portions of the affected application. Successfully exploiting this issue may allow attackers to execute arbitrary script code within the context of the web browser and steal cookie-based authentication credentials.
http://drupal.org/node/207891
Exploit / POC
Drupal Stock 'stock quote' Page Authentication Bypass Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Drupal Stock 'stock quote' Page Authentication Bypass Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Drupal Stock 6.x-1.x-dev
Solution:
The vendor has released an update. Please see the references for more information.
Drupal Stock 6.x-1.x-dev
-
Drupal stock-6.x-1.0.tar.gz
http://ftp.drupal.org/files/projects/stock-6.x-1.0.tar.gz
References
Drupal Stock 'stock quote' Page Authentication Bypass Vulnerability
References:
References:
- Stock Module Homepage (Drupal)
- SA-2008-055 - Stock - Cross site scripting (Drupal)