Drupal FileField Multiple HTML Injection Vulnerabilities
BID:40923
Info
Drupal FileField Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 40923 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-1958 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 17 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Peter Wolanin of the Drupal security team and Justin Klein Keane |
| Vulnerable: |
Drupal FileField 6.x-3.3 Drupal FileField 6.x-3.2 Drupal FileField 6.x-3.1 Drupal FileField 5.x-2.4 Drupal FileField 5.x-2.3 |
| Not Vulnerable: |
Drupal FileField 6.x-3.4 Drupal FileField 5.x-2.5 |
Discussion
Drupal FileField Multiple HTML Injection Vulnerabilities
The FileField module for Drupal is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
The following versions of FileField are vulnerable:
6.x prior to 6.x-2.5
5.x prior to 5.x-3.4
The FileField module for Drupal is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
The following versions of FileField are vulnerable:
6.x prior to 6.x-2.5
5.x prior to 5.x-3.4
Exploit / POC
Drupal FileField Multiple HTML Injection Vulnerabilities
An attacker can exploit these issues through a browser.
An attacker can exploit these issues through a browser.
References
Drupal FileField Multiple HTML Injection Vulnerabilities
References:
References:
- Drupal Homepage (Drupal)
- SA-CONTRIB-2010-066 - FileField - Cross Site Scripting (Drupal)