Drupal OpenSocial Shindig-Integrator Module HTML Injection Vulnerability
BID:36862
Info
Drupal OpenSocial Shindig-Integrator Module HTML Injection Vulnerability
| Bugtraq ID: | 36862 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2009 12:00AM |
| Updated: | Oct 29 2009 04:57PM |
| Credit: | Tony Mobily |
| Vulnerable: |
Drupal OpenSocial Shindig-Integrator 6.x-2.0 Drupal OpenSocial Shindig-Integrator 5.x |
| Not Vulnerable: |
Drupal OpenSocial Shindig-Integrator 6.x-2.1 |
Discussion
Drupal OpenSocial Shindig-Integrator Module HTML Injection Vulnerability
The OpenSocial Shindig-Integrator module for Drupal is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
This issue affects versions prior to OpenSocial Shindig-Integrator 6.x-2.1.
The OpenSocial Shindig-Integrator module for Drupal is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
This issue affects versions prior to OpenSocial Shindig-Integrator 6.x-2.1.
Exploit / POC
Drupal OpenSocial Shindig-Integrator Module HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Drupal OpenSocial Shindig-Integrator Module HTML Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Drupal OpenSocial Shindig-Integrator 6.x-2.0
Drupal OpenSocial Shindig-Integrator 5.x
Solution:
Updates are available. Please see the references for details.
Drupal OpenSocial Shindig-Integrator 6.x-2.0
-
ShindigIntegrator-6.x-2.1.tar.gz
http://ftp.drupal.org/files/projects/ShindigIntegrator-6.x-2.1.tar.gz
Drupal OpenSocial Shindig-Integrator 5.x
-
ShindigIntegrator-6.x-2.1.tar.gz
http://ftp.drupal.org/files/projects/ShindigIntegrator-6.x-2.1.tar.gz
References
Drupal OpenSocial Shindig-Integrator Module HTML Injection Vulnerability
References:
References: