Drupal Domain Access Module Security Bypass and HTML Injection Vulnerabilities
BID:43422
Info
Drupal Domain Access Module Security Bypass and HTML Injection Vulnerabilities
| Bugtraq ID: | 43422 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2010 12:00AM |
| Updated: | Sep 22 2010 12:00AM |
| Credit: | Sam Oldak, brt and Nirbhasa Magee |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Drupal Domain Access Module Security Bypass and HTML Injection Vulnerabilities
Drupal Domain Access module is prone to a security-bypass vulnerability and an HTML-injection vulnerability because it fails to properly validate user permissions and sanitize user-supplied input.
An attacker may leverage the HTML-injection issue to inject hostile HTML and script code that would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. The attacker may leverage the security-bypass issue to bypass certain security restrictions and perform unauthorized actions in the affected application.
The following are affected:
Domain access module for Drupal 5.x prior to 5.x-1.15
Domain access module for Drupal 6.x prior to 6.x.2.6
Domain access module for Drupal 7.x prior to 7.x.2.4
Drupal Domain Access module is prone to a security-bypass vulnerability and an HTML-injection vulnerability because it fails to properly validate user permissions and sanitize user-supplied input.
An attacker may leverage the HTML-injection issue to inject hostile HTML and script code that would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. The attacker may leverage the security-bypass issue to bypass certain security restrictions and perform unauthorized actions in the affected application.
The following are affected:
Domain access module for Drupal 5.x prior to 5.x-1.15
Domain access module for Drupal 6.x prior to 6.x.2.6
Domain access module for Drupal 7.x prior to 7.x.2.4
Exploit / POC
Drupal Domain Access Module Security Bypass and HTML Injection Vulnerabilities
Attackers can use a browser to exploit the issues.
Attackers can use a browser to exploit the issues.
Solution / Fix
Drupal Domain Access Module Security Bypass and HTML Injection Vulnerabilities
Solution:
The vendor has released updates. Please see the references for details.
Solution:
The vendor has released updates. Please see the references for details.
References
Drupal Domain Access Module Security Bypass and HTML Injection Vulnerabilities
References:
References: