Drupad Module For Drupal Cross Site Request Forgery Vulnerability
BID:41679
Info
Drupad Module For Drupal Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 41679 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2010 12:00AM |
| Updated: | Jul 14 2010 12:00AM |
| Credit: | Heine Deelstra of the Drupal security team |
| Vulnerable: |
Drupad Drupad 6.x-1.0 |
| Not Vulnerable: |
Drupad Drupad 6.x-1.1 |
Discussion
Drupad Module For Drupal Cross Site Request Forgery Vulnerability
The Drupad module for Drupal is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, or delete certain data. Other attacks are also possible.
Versions prior to Drupad 6.x-1.1 are vulnerable.
The Drupad module for Drupal is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, or delete certain data. Other attacks are also possible.
Versions prior to Drupad 6.x-1.1 are vulnerable.
Exploit / POC
Drupad Module For Drupal Cross Site Request Forgery Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Drupad Module For Drupal Cross Site Request Forgery Vulnerability
Solution:
Updates are available; please see the references for more information.
Drupad Drupad 6.x-1.0
Solution:
Updates are available; please see the references for more information.
Drupad Drupad 6.x-1.0
-
Drupad drupad-6.x-1.1.tar.gz
http://ftp.drupal.org/files/projects/drupad-6.x-1.1.tar.gz
References
Drupad Module For Drupal Cross Site Request Forgery Vulnerability
References:
References:
- Drupad Homepage (Drupad)
- Drupal Language Switcher Dropdown Homepage (Drupal)
- SA-CONTRIB-2010-074 - Drupad - Cross-site request forgery (Drupal)