Drupal Views Module HTML Injection and Cross Site Request Forgery Vulnerabilities
BID:40936
Info
Drupal Views Module HTML Injection and Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 40936 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2010 12:00AM |
| Updated: | May 07 2015 05:14PM |
| Credit: | Martin Barbella, Earl Miles |
| Vulnerable: |
Drupal Views 6.x-2.9 Drupal Views 6.x-2.8 Drupal Views 6.x-2.6 Drupal Views 6.x-2.5 Drupal Views 6.x-2.2 Drupal Views 6.X-2.1 Drupal Views 6.x-2.0 Drupal Views 5.x-1.7 Drupal Views 5.x-1.6 |
| Not Vulnerable: |
Drupal Views 6.X-2.11 Drupal Views 5.X-1.8 |
Discussion
Drupal Views Module HTML Injection and Cross Site Request Forgery Vulnerabilities
The Views module for Drupal is prone to an HTML-injection vulnerability and a cross-site request-forgery vulnerability.
An attacker can exploit these issues to execute arbitrary script code in a user's browser in the context of the application, steal cookie-based authentication credentials, perform unauthorized actions, and disclose or modify sensitive information. Other attacks may also be possible.
Versions prior to Views 5.x-1.8 and 6.x-2.11are vulnerable.
The Views module for Drupal is prone to an HTML-injection vulnerability and a cross-site request-forgery vulnerability.
An attacker can exploit these issues to execute arbitrary script code in a user's browser in the context of the application, steal cookie-based authentication credentials, perform unauthorized actions, and disclose or modify sensitive information. Other attacks may also be possible.
Versions prior to Views 5.x-1.8 and 6.x-2.11are vulnerable.
Exploit / POC
Drupal Views Module HTML Injection and Cross Site Request Forgery Vulnerabilities
An attacker can exploit these issues through a browser. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into visiting a malicious site.
An attacker can exploit these issues through a browser. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into visiting a malicious site.
References
Drupal Views Module HTML Injection and Cross Site Request Forgery Vulnerabilities
References:
References:
- Drupal Homepage (Drupal)
- Views Homepage (Drupal)
- SA-CONTRIB-2010-067 - Views - Multiple vulnerabilities (Drupal)