Drupal Internationalization Module Security Bypass Vulnerability
BID:33283
Info
Drupal Internationalization Module Security Bypass Vulnerability
| Bugtraq ID: | 33283 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2009 12:00AM |
| Updated: | Jan 16 2009 09:12PM |
| Credit: | Wolfgang Ziegler and by Nat Catchpole of the Drupal security team. |
| Vulnerable: |
Drupal Internationalization 5.x 2.3 Drupal Internationalization 5.x 2.2 Drupal Internationalization 5.x 2.2 Drupal Internationalization 5.x 1.x-dev Drupal Internationalization 5.x 1.1 |
| Not Vulnerable: |
Drupal Internationalization 5.x 2.5 |
Discussion
Drupal Internationalization Module Security Bypass Vulnerability
The Internationalization module for Drupal is prone to a security-bypass vulnerability that may allow attackers to gain access to sensitive areas of the application without the appropriate privileges.
This issue affects versions prior to Internationalization module 5.x-2.5.
The Internationalization module for Drupal is prone to a security-bypass vulnerability that may allow attackers to gain access to sensitive areas of the application without the appropriate privileges.
This issue affects versions prior to Internationalization module 5.x-2.5.
Exploit / POC
Drupal Internationalization Module Security Bypass Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Drupal Internationalization Module Security Bypass Vulnerability
Solution:
The vendor has released fixes and an advisory. Please see the references for more information.
Solution:
The vendor has released fixes and an advisory. Please see the references for more information.
References
Drupal Internationalization Module Security Bypass Vulnerability
References:
References: