Drupal Memcache Security Bypass and Cross-Site Scripting Vulnerabilities
BID:43606
Info
Drupal Memcache Security Bypass and Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 43606 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-5275 CVE-2010-5276 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2010 12:00AM |
| Updated: | Oct 10 2012 06:10PM |
| Credit: | Justin James Grevich (jgrevich), Moshe Weitzman, of the Drupal Security Team |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Drupal Memcache Security Bypass and Cross-Site Scripting Vulnerabilities
The Memcache module for Drupal is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. The module is also prone to a security-bypass vulnerability which leads to a role change.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials or bypass security restrictions to perform unauthorized actions; this may aid in launching further attacks.
Memcache for Drupal 6.x versions prior to 6.x-1.6 are vulnerable.
Memcache for Drupal 5.x versions prior to 5.x-1.10 are vulnerable.
The Memcache module for Drupal is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. The module is also prone to a security-bypass vulnerability which leads to a role change.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials or bypass security restrictions to perform unauthorized actions; this may aid in launching further attacks.
Memcache for Drupal 6.x versions prior to 6.x-1.6 are vulnerable.
Memcache for Drupal 5.x versions prior to 5.x-1.10 are vulnerable.
Exploit / POC
Drupal Memcache Security Bypass and Cross-Site Scripting Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
Drupal Memcache Security Bypass and Cross-Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the reference for more details.
Solution:
Updates are available. Please see the reference for more details.
References
Drupal Memcache Security Bypass and Cross-Site Scripting Vulnerabilities
References:
References: