Drupal Taxonomy Theme Module 'Vocabulary name' HTML Injection Vulnerability
BID:33923
Info
Drupal Taxonomy Theme Module 'Vocabulary name' HTML Injection Vulnerability
| Bugtraq ID: | 33923 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2009 12:00AM |
| Updated: | Mar 03 2009 04:56PM |
| Credit: | Justin Klein Keane |
| Vulnerable: |
Drupal Taxonomy Theme 5.x-1.1 |
| Not Vulnerable: |
Drupal Taxonomy Theme 5.x-1.2 |
Discussion
Drupal Taxonomy Theme Module 'Vocabulary name' HTML Injection Vulnerability
The Taxonomy Theme module for Drupal is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Note that to exploit this issue, attackers require valid authentication credentials with 'administer taxonomy' privileges.
Versions prior to Taxonomy Theme 5.x-1.2 are vulnerable.
http://drupal.org/node/207891
The Taxonomy Theme module for Drupal is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Note that to exploit this issue, attackers require valid authentication credentials with 'administer taxonomy' privileges.
Versions prior to Taxonomy Theme 5.x-1.2 are vulnerable.
http://drupal.org/node/207891
Exploit / POC
Drupal Taxonomy Theme Module 'Vocabulary name' HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Drupal Taxonomy Theme Module 'Vocabulary name' HTML Injection Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Drupal Taxonomy Theme 5.x-1.1
Solution:
The vendor has released an update. Please see the references for more information.
Drupal Taxonomy Theme 5.x-1.1
-
Drupal taxonomy_theme-5.x-1.2.tar.gz
http://ftp.drupal.org/files/projects/taxonomy_theme-5.x-1.2.tar.gz
References
Drupal Taxonomy Theme Module 'Vocabulary name' HTML Injection Vulnerability
References:
References:
- Drupal Language Switcher Dropdown Homepage (Drupal)
- Drupal Taxonomy Theme Module XSS Vulnerability (Justin Klein Keane)
- Taxonomy Theme Homepage (Taxonomy Theme)