Block Queue Module For Drupal Cross Site Request Forgery Vulnerability
BID:41101
Info
Block Queue Module For Drupal Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 41101 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2010 12:00AM |
| Updated: | Jun 23 2010 12:00AM |
| Credit: | mr.baileys of the Drupal Security Team |
| Vulnerable: |
George Gongadze Block Queue 0 |
| Not Vulnerable: | |
Discussion
Block Queue Module For Drupal Cross Site Request Forgery Vulnerability
The Block Queue module for Drupal is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, or delete certain data. Other attacks are also possible.
The Block Queue module for Drupal is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, or delete certain data. Other attacks are also possible.
Exploit / POC
Block Queue Module For Drupal Cross Site Request Forgery Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Block Queue Module For Drupal Cross Site Request Forgery Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Block Queue Module For Drupal Cross Site Request Forgery Vulnerability
References:
References:
- Block Queue - Homepage (George Gongadze)
- Drupal Language Switcher Dropdown Homepage (Drupal)
- SA-CONTRIB-2010-070 - Multiple vulnerabilities in multiple contributed modules (Drupal)