Drupal Nodequeue Module Node Title Security Bypass Vulnerability
BID:35602
Info
Drupal Nodequeue Module Node Title Security Bypass Vulnerability
| Bugtraq ID: | 35602 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 2009 12:00AM |
| Updated: | Jul 09 2009 08:16PM |
| Credit: | Ezra Barnett Gildesgame (ezra-g) |
| Vulnerable: |
Drupal Nodequeue 6.x-2.2 Drupal Nodequeue 6.X-2.1 Drupal Nodequeue 5.x-2.7 Drupal Nodequeue 5.x-2.6 |
| Not Vulnerable: |
Drupal Nodequeue 6.X-2.3 Drupal Nodequeue 5.x-2.8 |
Discussion
Drupal Nodequeue Module Node Title Security Bypass Vulnerability
The Nodequeue module for Drupal is prone to a security-bypass vulnerability that may allow attackers to perform actions without proper authorization.
Attackers can exploit this issue to bypass security restrictions to obtain sensitive information or perform unauthorized actions; this may aid in launching further attacks.
This issue affects versions prior to Nodequeue 5.x-2.8 and 6.x-2.3.
The Nodequeue module for Drupal is prone to a security-bypass vulnerability that may allow attackers to perform actions without proper authorization.
Attackers can exploit this issue to bypass security restrictions to obtain sensitive information or perform unauthorized actions; this may aid in launching further attacks.
This issue affects versions prior to Nodequeue 5.x-2.8 and 6.x-2.3.
Exploit / POC
Drupal Nodequeue Module Node Title Security Bypass Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Drupal Nodequeue Module Node Title Security Bypass Vulnerability
Solution:
The vendor has released fixes and an advisory. Please see the references for details.
Drupal Nodequeue 5.x-2.6
Drupal Nodequeue 6.X-2.1
Drupal Nodequeue 6.x-2.2
Drupal Nodequeue 5.x-2.7
Solution:
The vendor has released fixes and an advisory. Please see the references for details.
Drupal Nodequeue 5.x-2.6
-
Drupal nodequeue-5.x-2.8.tar.gz
http://ftp.drupal.org/files/projects/nodequeue-5.x-2.8.tar.gz
Drupal Nodequeue 6.X-2.1
-
Drupal nodequeue-6.x-2.3.tar.gz
http://ftp.drupal.org/files/projects/nodequeue-6.x-2.3.tar.gz
Drupal Nodequeue 6.x-2.2
-
Drupal nodequeue-6.x-2.3.tar.gz
http://ftp.drupal.org/files/projects/nodequeue-6.x-2.3.tar.gz
Drupal Nodequeue 5.x-2.7
-
Drupal nodequeue-5.x-2.8.tar.gz
http://ftp.drupal.org/files/projects/nodequeue-5.x-2.8.tar.gz
References
Drupal Nodequeue Module Node Title Security Bypass Vulnerability
References:
References:
- Drupal Language Switcher Dropdown Homepage (Drupal)
- Nodequeue Homepage (Drupal)
- SA-CONTRIB-2009-041 - Nodequeue - Access bypass (Drupal)