Drupal Cosign Module Multiple SQL Injection Vulnerabilities
BID:48176
Info
Drupal Cosign Module Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 48176 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2011 12:00AM |
| Updated: | Jun 08 2011 12:00AM |
| Credit: | Steven Merrill |
| Vulnerable: |
University of Michigan cosign 6.X-1.6 University of Michigan cosign 6.X-1.5 University of Michigan cosign 6.X-1.4 |
| Not Vulnerable: |
University of Michigan cosign 6.X-1.7 |
Discussion
Drupal Cosign Module Multiple SQL Injection Vulnerabilities
The 'Cosign' module for Drupal is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
The 'Cosign' module for Drupal is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Exploit / POC
Drupal Cosign Module Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Drupal Cosign Module Multiple SQL Injection Vulnerabilities
Solution:
Updates are available. Please see the references for more details.
University of Michigan cosign 6.X-1.6
University of Michigan cosign 6.X-1.5
University of Michigan cosign 6.X-1.4
Solution:
Updates are available. Please see the references for more details.
University of Michigan cosign 6.X-1.6
-
cosign-6.x-1.7.tar.gz
http://drupal.org/node/1181592
University of Michigan cosign 6.X-1.5
-
cosign-6.x-1.7.tar.gz
http://drupal.org/node/1181592
University of Michigan cosign 6.X-1.4
-
cosign-6.x-1.7.tar.gz
http://drupal.org/node/1181592
References
Drupal Cosign Module Multiple SQL Injection Vulnerabilities
References:
References:
- Cosign Homepage (University of Michigan)
- Cosign Homepage (Drupal)
- Drupal Homepage (Drupal)
- SA-CONTRIB-2011-022 - Cosign - SQL Injection (Drupal)