Drupal Advanced Book Blocks HTML Injection and Cross Site Request Forgery Vulnerabilities
BID:43250
Info
Drupal Advanced Book Blocks HTML Injection and Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 43250 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2010 12:00AM |
| Updated: | Jan 05 2011 08:42PM |
| Credit: | Matt Chapman |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Drupal Advanced Book Blocks HTML Injection and Cross Site Request Forgery Vulnerabilities
The Advanced Book Blocks for Drupal is prone to an HTML-injection vulnerability and a cross-site request-forgery vulnerability.
An attacker can exploit these issues to execute arbitrary script code in a user's browser in the context of the application, steal cookie-based authentication credentials, perform unauthorized actions, and disclose or modify sensitive information. Other attacks may also be possible.
Versions prior to Advanced Book Blocks d 6.x-2.2 are vulnerable.
The Advanced Book Blocks for Drupal is prone to an HTML-injection vulnerability and a cross-site request-forgery vulnerability.
An attacker can exploit these issues to execute arbitrary script code in a user's browser in the context of the application, steal cookie-based authentication credentials, perform unauthorized actions, and disclose or modify sensitive information. Other attacks may also be possible.
Versions prior to Advanced Book Blocks d 6.x-2.2 are vulnerable.
Exploit / POC
Drupal Advanced Book Blocks HTML Injection and Cross Site Request Forgery Vulnerabilities
An attacker can exploit these issues through a browser. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into visiting a malicious site.
An attacker can exploit these issues through a browser. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into visiting a malicious site.
Solution / Fix
Drupal Advanced Book Blocks HTML Injection and Cross Site Request Forgery Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Drupal Advanced Book Blocks HTML Injection and Cross Site Request Forgery Vulnerabilities
References:
References:
- Drupal Homepage (Drupal)
- DRUPAL-SA-CONTRIB-2010-092 (Drupal)