Drupal Advanced Taxonomy Blocks Module HTML Injection and Cross Site Request Forgery Vulnerabilities
BID:43252
Info
Drupal Advanced Taxonomy Blocks Module HTML Injection and Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 43252 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2010 12:00AM |
| Updated: | Sep 15 2010 12:00AM |
| Credit: | mr.baileys |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Drupal Advanced Taxonomy Blocks Module HTML Injection and Cross Site Request Forgery Vulnerabilities
The Advanced Taxonomy Blocks module for Drupal is prone to an HTML-injection vulnerability and a cross-site request-forgery vulnerability.
An attacker can exploit these issues to execute arbitrary script code in a user's browser in the context of the application, steal cookie-based authentication credentials, perform unauthorized actions, and disclose or modify sensitive information. Other attacks may also be possible.
Versions prior to Advanced Taxonomy Blocks 6.x-3.4 are vulnerable.
The Advanced Taxonomy Blocks module for Drupal is prone to an HTML-injection vulnerability and a cross-site request-forgery vulnerability.
An attacker can exploit these issues to execute arbitrary script code in a user's browser in the context of the application, steal cookie-based authentication credentials, perform unauthorized actions, and disclose or modify sensitive information. Other attacks may also be possible.
Versions prior to Advanced Taxonomy Blocks 6.x-3.4 are vulnerable.