Drupal Troll Module 'Form API' Cross-Site Request Forgery Vulnerability
BID:33738
Info
Drupal Troll Module 'Form API' Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 33738 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2009 12:00AM |
| Updated: | Feb 11 2009 11:48PM |
| Credit: | Heine Deelstra and David Kent Norman |
| Vulnerable: |
Drupal Troll Module 0 |
| Not Vulnerable: | |
Discussion
Drupal Troll Module 'Form API' Cross-Site Request Forgery Vulnerability
The Troll module for Drupal is prone to a cross-site request-forgery vulnerability.
Attackers may exploit this issue to perform unauthorized actions, compromise the affected application, and modify administration settings. Other attacks are also possible.
The Troll module for Drupal is prone to a cross-site request-forgery vulnerability.
Attackers may exploit this issue to perform unauthorized actions, compromise the affected application, and modify administration settings. Other attacks are also possible.
Exploit / POC
Drupal Troll Module 'Form API' Cross-Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into visiting a malicious webpage.
To exploit this issue, an attacker must entice an unsuspecting victim into visiting a malicious webpage.
Solution / Fix
Drupal Troll Module 'Form API' Cross-Site Request Forgery Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Drupal Troll Module 'Form API' Cross-Site Request Forgery Vulnerability
References:
References: