Drupal Live Module Node Edit Privilege Escalation Vulnerability
BID:35884
Info
Drupal Live Module Node Edit Privilege Escalation Vulnerability
| Bugtraq ID: | 35884 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 30 2009 12:00AM |
| Updated: | Jul 30 2009 10:34PM |
| Credit: | Roderik Muit |
| Vulnerable: |
Gurpartap Singh Live 6.x-1.0 |
| Not Vulnerable: |
Gurpartap Singh Live 6.x-1.2 |
Discussion
Drupal Live Module Node Edit Privilege Escalation Vulnerability
The Live module for Drupal is prone to a privilege-escalation vulnerability.
Attackers can exploit this issue to gain elevated privileges within the application, which may aid in launching further attacks.
This issue affects Live 6.x prior to 6.x-1.2.
The Live module for Drupal is prone to a privilege-escalation vulnerability.
Attackers can exploit this issue to gain elevated privileges within the application, which may aid in launching further attacks.
This issue affects Live 6.x prior to 6.x-1.2.
Exploit / POC
Drupal Live Module Node Edit Privilege Escalation Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Drupal Live Module Node Edit Privilege Escalation Vulnerability
Solution:
The vendor has released fixes and an advisory. Please see the references for details.
Gurpartap Singh Live 6.x-1.0
Solution:
The vendor has released fixes and an advisory. Please see the references for details.
Gurpartap Singh Live 6.x-1.0
-
Gurpartap Singh live-6.x-1.2.tar.gz
http://ftp.drupal.org/files/projects/live-6.x-1.2.tar.gz
References
Drupal Live Module Node Edit Privilege Escalation Vulnerability
References:
References: