Drupal Webform Module Cross Site Scripting and Arbitrary File Upload Vulnerabilities
BID:47915
Info
Drupal Webform Module Cross Site Scripting and Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 47915 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2011 12:00AM |
| Updated: | May 19 2011 12:00AM |
| Credit: | Justin Klein Keane of the Drupal Security Team |
| Vulnerable: |
Drupal Webform 7.x-3.9 Drupal Webform 6.x-3.9 Drupal Webform 6.x-2.10 |
| Not Vulnerable: |
Drupal Webform 7.x-3.11 Drupal Webform 7.x-3.10 Drupal Webform 6.x-3.11 Drupal Webform 6.x-3.10 |
Discussion
Drupal Webform Module Cross Site Scripting and Arbitrary File Upload Vulnerabilities
The Webform module for Drupal is prone to a cross-site scripting vulnerability and an arbitrary-file-upload vulnerability because it fails to properly sanitize user-supplied input.
Successful exploitation requires a user with permission to either 'create webform content' or 'administer nodes' and a role that can submit a webform that accepts file uploads.
Attackers can exploit these issues to steal cookie-based authentication information, execute arbitrary scripts in the context of the browser, upload and execute arbitrary files in the context of the webserver, and launch other attacks.
Webform versions 6.x-2.10, 6.x-3.9, and 7.x-3.9 are affected.
The Webform module for Drupal is prone to a cross-site scripting vulnerability and an arbitrary-file-upload vulnerability because it fails to properly sanitize user-supplied input.
Successful exploitation requires a user with permission to either 'create webform content' or 'administer nodes' and a role that can submit a webform that accepts file uploads.
Attackers can exploit these issues to steal cookie-based authentication information, execute arbitrary scripts in the context of the browser, upload and execute arbitrary files in the context of the webserver, and launch other attacks.
Webform versions 6.x-2.10, 6.x-3.9, and 7.x-3.9 are affected.
Exploit / POC
Drupal Webform Module Cross Site Scripting and Arbitrary File Upload Vulnerabilities
Attackers can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
Drupal Webform Module Cross Site Scripting and Arbitrary File Upload Vulnerabilities
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
Drupal Webform Module Cross Site Scripting and Arbitrary File Upload Vulnerabilities
References:
References:
- Drupal Homepage (Drupal)
- Webform Project Homepage (Drupal)
- SA-CONTRIB-2011-021 - Webform - Multiple Vulnerabilities (Drupal)