Drupal Security Bypass Vulnerability and SQL Injection Weakness
BID:33285
Info
Drupal Security Bypass Vulnerability and SQL Injection Weakness
| Bugtraq ID: | 33285 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 14 2009 12:00AM |
| Updated: | Jan 19 2009 04:02PM |
| Credit: | Wolfgang Ziegler, Derek Wright of the Drupal Security Team. |
| Vulnerable: |
Red Hat Fedora 9 Drupal Drupal 6.7 Drupal Drupal 6.6 Drupal Drupal 6.5 Drupal Drupal 6.4 Drupal Drupal 6.3 Drupal Drupal 6.2 Drupal Drupal 6.1 Drupal Drupal 6.0 Drupal Drupal 5.9 Drupal Drupal 5.8 Drupal Drupal 5.7 Drupal Drupal 5.6 Drupal Drupal 5.5 Drupal Drupal 5.4 Drupal Drupal 5.3 Drupal Drupal 5.2 Drupal Drupal 5.13 Drupal Drupal 5.12 Drupal Drupal 5.11 Drupal Drupal 5.10 Drupal Drupal 5.1 revision 1.1 Drupal Drupal 5.1 Drupal Drupal 5.0 |
| Not Vulnerable: |
Drupal Drupal 6.9 Drupal Drupal 5.15 |
Discussion
Drupal Security Bypass Vulnerability and SQL Injection Weakness
Drupal is prone to a security-bypass vulnerability and a weakness that attackers can leverage to launch SQL-injection attacks.
Exploiting these issues may allow attackers to gain access to sensitive areas of the application without the appropriate privileges or to perform SQL-injection attacks and carry out unauthorized actions on the underlying database.
Versions prior to Drupal 5.15 and 6.9 are vulnerable. Note that the security-bypass issue affects only Drupal 6.x.
Drupal is prone to a security-bypass vulnerability and a weakness that attackers can leverage to launch SQL-injection attacks.
Exploiting these issues may allow attackers to gain access to sensitive areas of the application without the appropriate privileges or to perform SQL-injection attacks and carry out unauthorized actions on the underlying database.
Versions prior to Drupal 5.15 and 6.9 are vulnerable. Note that the security-bypass issue affects only Drupal 6.x.
Exploit / POC
Drupal Security Bypass Vulnerability and SQL Injection Weakness
An attacker can exploit these issues via a web browser.
An attacker can exploit these issues via a web browser.
Solution / Fix
Drupal Security Bypass Vulnerability and SQL Injection Weakness
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
References
Drupal Security Bypass Vulnerability and SQL Injection Weakness
References:
References: