Drupal Imagemenu Module HTML Injection and Cross Site Request Forgery Vulnerabilities
BID:43598
Info
Drupal Imagemenu Module HTML Injection and Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 43598 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2010 12:00AM |
| Updated: | Sep 29 2010 12:00AM |
| Credit: | Joachim Noreiko and Ivo Van Geertruyen. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Drupal Imagemenu Module HTML Injection and Cross Site Request Forgery Vulnerabilities
The Imagemenu module for Drupal is prone to multiple HTML-injection vulnerabilities and a cross-site request-forgery vulnerability because it fails to properly sanitize user-supplied input.
Exploiting these issues may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, delete certain data, execute arbitrary script or HTML code within the context of the browser, and steal cookie-based authentication credentials. Other attacks are also possible.
Versions prior to Imagemenu 5.x-1.2 and 6.x-1.3 are vulnerable.
The Imagemenu module for Drupal is prone to multiple HTML-injection vulnerabilities and a cross-site request-forgery vulnerability because it fails to properly sanitize user-supplied input.
Exploiting these issues may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, delete certain data, execute arbitrary script or HTML code within the context of the browser, and steal cookie-based authentication credentials. Other attacks are also possible.
Versions prior to Imagemenu 5.x-1.2 and 6.x-1.3 are vulnerable.
Exploit / POC
Drupal Imagemenu Module HTML Injection and Cross Site Request Forgery Vulnerabilities
An attacker can exploit HTML-injection issues through a browser. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into visiting a malicious site.
An attacker can exploit HTML-injection issues through a browser. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into visiting a malicious site.
Solution / Fix
Drupal Imagemenu Module HTML Injection and Cross Site Request Forgery Vulnerabilities
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
Drupal Imagemenu Module HTML Injection and Cross Site Request Forgery Vulnerabilities
References:
References:
- Drupal Homepage (Drupal)
- Imagemenu Homepage (Drupal)
- SA-CONTRIB-2010-097 - Imagemenu - Multiple vulnerabilities (Drupal)