Drupal Views Content Construction Kit SQL Injection Vulnerability
BID:32895
Info
Drupal Views Content Construction Kit SQL Injection Vulnerability
| Bugtraq ID: | 32895 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2008 12:00AM |
| Updated: | Dec 30 2008 04:52PM |
| Credit: | Peter Fisera and Mariano D'Agostino |
| Vulnerable: |
Red Hat Fedora 9 Drupal Views 6.X-2.1 Drupal Views 6.x-2.0 |
| Not Vulnerable: |
Drupal Views 6.x-2.2 |
Discussion
Drupal Views Content Construction Kit SQL Injection Vulnerability
The Drupal Views module is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Views 6.x-2.2 are vulnerable.
The Drupal Views module is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Views 6.x-2.2 are vulnerable.
Exploit / POC
Drupal Views Content Construction Kit SQL Injection Vulnerability
An attacker can exploit these issues via a browser.
An attacker can exploit these issues via a browser.
Solution / Fix
Drupal Views Content Construction Kit SQL Injection Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Drupal Views 6.X-2.1
Drupal Views 6.x-2.0
Solution:
The vendor has released an update. Please see the references for more information.
Drupal Views 6.X-2.1
-
Drupal views-6.x-2.2.tar.gz
http://ftp.drupal.org/files/projects/views-6.x-2.2.tar.gz
Drupal Views 6.x-2.0
-
Drupal views-6.x-2.2.tar.gz
http://ftp.drupal.org/files/projects/views-6.x-2.2.tar.gz
References
Drupal Views Content Construction Kit SQL Injection Vulnerability
References:
References:
- SA-2008-075 - Views - SQL Injection (Drupal)
- Views Homepage (Drupal)