Drupal Contact and Menu Modules Multiple HTML Injection Vulnerabilities
BID:37372
Info
Drupal Contact and Menu Modules Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 37372 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4369 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2009 12:00AM |
| Updated: | Apr 13 2015 10:25PM |
| Credit: | mr.baileys and Justin Klein Keane |
| Vulnerable: |
Drupal Drupal 6.9 Drupal Drupal 6.7 Drupal Drupal 6.6 Drupal Drupal 6.5 Drupal Drupal 6.4 Drupal Drupal 6.3 Drupal Drupal 6.2 Drupal Drupal 6.14 Drupal Drupal 6.13 Drupal Drupal 6.12 Drupal Drupal 6.11 Drupal Drupal 6.10 Drupal Drupal 6.1 Drupal Drupal 6.0 Drupal Drupal 5.9 Drupal Drupal 5.8 Drupal Drupal 5.7 Drupal Drupal 5.6 Drupal Drupal 5.5 Drupal Drupal 5.4 Drupal Drupal 5.3 Drupal Drupal 5.20 Drupal Drupal 5.2 Drupal Drupal 5.19 Drupal Drupal 5.18 Drupal Drupal 5.17 Drupal Drupal 5.16 Drupal Drupal 5.15 Drupal Drupal 5.13 Drupal Drupal 5.12 Drupal Drupal 5.11 Drupal Drupal 5.10 Drupal Drupal 5.1 Drupal Drupal 5.0 |
| Not Vulnerable: |
Drupal Drupal 6.15 Drupal Drupal 5.21 |
Discussion
Drupal Contact and Menu Modules Multiple HTML Injection Vulnerabilities
Drupal is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content. These issues affect the Contact and Menu modules.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
These issues affect the following versions:
Drupal 5.x prior to 5.21
Drupal 6.x prior to 6.15
Drupal is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content. These issues affect the Contact and Menu modules.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
These issues affect the following versions:
Drupal 5.x prior to 5.21
Drupal 6.x prior to 6.15
Exploit / POC
Drupal Contact and Menu Modules Multiple HTML Injection Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
Drupal Contact and Menu Modules Multiple HTML Injection Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Drupal Drupal 6.14
Drupal Drupal 5.20
Solution:
Updates are available. Please see the references for details.
Drupal Drupal 6.14
-
Drupal SA-CORE-2009-009-6.14.patch
http://drupal.org/files/sa-core-2009-009/SA-CORE-2009-009-6.14.patch
Drupal Drupal 5.20
-
Drupal SA-CORE-2009-009-5.20.patch
http://drupal.org/files/sa-core-2009-009/SA-CORE-2009-009-5.20.patch
References
Drupal Contact and Menu Modules Multiple HTML Injection Vulnerabilities
References:
References: