Drupal EveryBlog Module Multiple Unspecified Vulnerabilities
BID:31656
Info
Drupal EveryBlog Module Multiple Unspecified Vulnerabilities
| Bugtraq ID: | 31656 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6136 CVE-2008-6137 CVE-2008-6134 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | Dan Hassel and unnamed members of the Drupal security team |
| Vulnerable: |
Drupal EveryBlog 0 |
| Not Vulnerable: | |
Discussion
Drupal EveryBlog Module Multiple Unspecified Vulnerabilities
The EveryBlog module for Drupal is prone to multiple vulnerabilities because it fails to sufficiently sanitize user-supplied input data.
Exploiting these vulnerabilities may allow attackers to:
- Execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user.
- Manipulate the SQL query logic to carry out unauthorized actions on the underlying database.
- Gain access to sensitive areas of the application without the appropriate privileges.
Versions up to and including EveryBlog 2.0 are vulnerable.
The EveryBlog module for Drupal is prone to multiple vulnerabilities because it fails to sufficiently sanitize user-supplied input data.
Exploiting these vulnerabilities may allow attackers to:
- Execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user.
- Manipulate the SQL query logic to carry out unauthorized actions on the underlying database.
- Gain access to sensitive areas of the application without the appropriate privileges.
Versions up to and including EveryBlog 2.0 are vulnerable.
Exploit / POC
Drupal EveryBlog Module Multiple Unspecified Vulnerabilities
Attackers can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice a victim to follow a malicious URI.
Attackers can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice a victim to follow a malicious URI.
Solution / Fix
Drupal EveryBlog Module Multiple Unspecified Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
NOTE: Drupal recommends disabling this module until the issues have been addressed.
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
NOTE: Drupal recommends disabling this module until the issues have been addressed.
References
Drupal EveryBlog Module Multiple Unspecified Vulnerabilities
References:
References:
- EveryBlog Homepage (Drupal)
- SA-2008-061 - EveryBlog - Multiple vulnerabilities (Drupal)
- Vendor Homepage (Drupal)