Drupal Links Package 'Title' HTML Injection Vulnerability
BID:35491
Info
Drupal Links Package 'Title' HTML Injection Vulnerability
| Bugtraq ID: | 35491 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2610 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2009 12:00AM |
| Updated: | Apr 13 2015 09:09PM |
| Credit: | Stéphane Corlosquet |
| Vulnerable: |
Drupal Links Package 6.x-1.1 Drupal Links Package 5.x-1.12 |
| Not Vulnerable: |
Drupal Links Package 6.x-1.2 Drupal Links Package 5.x-1.13 |
Discussion
Drupal Links Package 'Title' HTML Injection Vulnerability
The Links Package module for Drupal is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Note that to exploit this issue, attackers would need to have 'content create' privileges.
The Links Package module for Drupal is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Note that to exploit this issue, attackers would need to have 'content create' privileges.
Exploit / POC
Drupal Links Package 'Title' HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Drupal Links Package 'Title' HTML Injection Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
Drupal Links Package 'Title' HTML Injection Vulnerability
References:
References:
- [Security-news] SA-CONTRIB-2009-039 - Links Package - Cross Site Scripting (Drupal)
- links 5.x-1.13 (Drupal)
- links 6.x-1.2 (Drupal)
- Links Package Homepage (Drupal)