Studio theme pack Module For Drupal Cross Site Scripting Vulnerability
BID:40933
Info
Studio theme pack Module For Drupal Cross Site Scripting Vulnerability
| Bugtraq ID: | 40933 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2010 12:00AM |
| Updated: | Jun 16 2010 12:00AM |
| Credit: | Pelle Wessman |
| Vulnerable: |
Al Steffen Studio theme pack 6.x-1.x |
| Not Vulnerable: |
Al Steffen Studio theme pack 6.x-1.2 |
Discussion
Studio theme pack Module For Drupal Cross Site Scripting Vulnerability
The Studio theme pack module for Drupal is prone to cross-site scripting because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Studio theme pack 6.x versions prior to 6.x-1.2 are vulnerable.
The Studio theme pack module for Drupal is prone to cross-site scripting because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Studio theme pack 6.x versions prior to 6.x-1.2 are vulnerable.
Exploit / POC
Studio theme pack Module For Drupal Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Studio theme pack Module For Drupal Cross Site Scripting Vulnerability
Solution:
This issue has been fixed in Studio theme pack 6.x-1.2. Please see the references for details.
Al Steffen Studio theme pack 6.x-1.x
Solution:
This issue has been fixed in Studio theme pack 6.x-1.2. Please see the references for details.
Al Steffen Studio theme pack 6.x-1.x
-
Al Steffen Studio theme pack 6.x-1.2
http://ftp.drupal.org/files/projects/studio-6.x-1.2.tar.gz
References
Studio theme pack Module For Drupal Cross Site Scripting Vulnerability
References:
References:
- Drupal Language Switcher Dropdown Homepage (Drupal)
- Studio theme pack - Homepage (Al Steffen)
- SA-CONTRIB-2010-063 - Studio theme pack - Cross Site Scripting (Drupal)