Drupal Project issue tracking Security Bypass and Cross Site Scripting Vulnerabilities
BID:33164
Info
Drupal Project issue tracking Security Bypass and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 33164 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2009 12:00AM |
| Updated: | Jan 08 2009 05:52PM |
| Credit: | Damien Tournoud, Derek Wright |
| Vulnerable: |
Drupal Project issue tracking 5.x-2.x Drupal Project issue tracking 5.x-2.2 Drupal Project issue tracking 5.x-2.0 Drupal Project issue tracking 5.x-1.x Drupal Project issue tracking 5.x-1.3 |
| Not Vulnerable: |
Drupal Project issue tracking 5.x-2.3 |
Discussion
Drupal Project issue tracking Security Bypass and Cross Site Scripting Vulnerabilities
The 'Project issue tracking' module for Drupal is prone to a security-bypass and a cross-site scripting vulnerability because it fails to properly validate user credentials and sanitize user-supplied input.
An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
The attacker may leverage the security-bypass issue to reset an arbitrary user's password and gain access to the user's account.
These issues affect 'Project issue tracking' 5.x (prior to 5.x-2.3).
The 'Project issue tracking' module for Drupal is prone to a security-bypass and a cross-site scripting vulnerability because it fails to properly validate user credentials and sanitize user-supplied input.
An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
The attacker may leverage the security-bypass issue to reset an arbitrary user's password and gain access to the user's account.
These issues affect 'Project issue tracking' 5.x (prior to 5.x-2.3).
Exploit / POC
Drupal Project issue tracking Security Bypass and Cross Site Scripting Vulnerabilities
Attackers can use a browser to exploit these issues. For a cross-site scripting attack, attackers will entice unsuspecting users to follow a malicious URI.
Attackers can use a browser to exploit these issues. For a cross-site scripting attack, attackers will entice unsuspecting users to follow a malicious URI.
Solution / Fix
Drupal Project issue tracking Security Bypass and Cross Site Scripting Vulnerabilities
Solution:
The vendor has released an update. Please see the references for more information.
Drupal Project issue tracking 5.x-2.2
Drupal Project issue tracking 5.x-2.0
Drupal Project issue tracking 5.x-2.x
Drupal Project issue tracking 5.x-1.3
Drupal Project issue tracking 5.x-1.x
Solution:
The vendor has released an update. Please see the references for more information.
Drupal Project issue tracking 5.x-2.2
-
Drupal project_issue-5.x-2.3.tar.gz
http://ftp.drupal.org/files/projects/project_issue-5.x-2.3.tar.gz
Drupal Project issue tracking 5.x-2.0
-
Drupal project_issue-5.x-2.3.tar.gz
http://ftp.drupal.org/files/projects/project_issue-5.x-2.3.tar.gz
Drupal Project issue tracking 5.x-2.x
-
Drupal project_issue-5.x-2.3.tar.gz
http://ftp.drupal.org/files/projects/project_issue-5.x-2.3.tar.gz
Drupal Project issue tracking 5.x-1.3
-
Drupal project_issue-5.x-2.3.tar.gz
http://ftp.drupal.org/files/projects/project_issue-5.x-2.3.tar.gz
Drupal Project issue tracking 5.x-1.x
-
Drupal project_issue-5.x-2.3.tar.gz
http://ftp.drupal.org/files/projects/project_issue-5.x-2.3.tar.gz
References
Drupal Project issue tracking Security Bypass and Cross Site Scripting Vulnerabilities
References:
References: