Drupal Dex Unspecified HTML Injection Vulnerability
BID:36559
Info
Drupal Dex Unspecified HTML Injection Vulnerability
| Bugtraq ID: | 36559 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3650 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2009 12:00AM |
| Updated: | Apr 13 2015 09:06PM |
| Credit: | St�?©phane Corlosquet |
| Vulnerable: |
Drupal Dex 6.x-1.0-rc1 Drupal Dex 5.x-1.0 |
| Not Vulnerable: | |
Discussion
Drupal Dex Unspecified HTML Injection Vulnerability
The Dex component for Drupal is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits would allow attackers to execute arbitrary script and HTML code in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Dex 5.x-1.0 and 6.x-1.0rc1 are vulnerable.
The Dex component for Drupal is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits would allow attackers to execute arbitrary script and HTML code in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Dex 5.x-1.0 and 6.x-1.0rc1 are vulnerable.
Exploit / POC
Drupal Dex Unspecified HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Drupal Dex Unspecified HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
NOTE: The Drupal maintainers report that this module is no longer supported. They recommend that users disable the affected module until a suitable update or replacement becomes available.
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
NOTE: The Drupal maintainers report that this module is no longer supported. They recommend that users disable the affected module until a suitable update or replacement becomes available.
References
Drupal Dex Unspecified HTML Injection Vulnerability
References:
References: