Drupal Secure Password Hashes Module Security Bypass Vulnerability
BID:48530
Info
Drupal Secure Password Hashes Module Security Bypass Vulnerability
| Bugtraq ID: | 48530 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 29 2011 12:00AM |
| Updated: | Jul 29 2011 12:00AM |
| Credit: | PWolanin |
| Vulnerable: |
Drupal Secure Password Hashes 6.X-1.0 Drupal Secure Password Hashes 5.X-1.4 |
| Not Vulnerable: |
Drupal Secure Password Hashes 6.X-1.1 Drupal Secure Password Hashes 5.x-1.5 |
Discussion
Drupal Secure Password Hashes Module Security Bypass Vulnerability
The Secure Password Hashes module for Drupal is prone to a security-bypass vulnerability.
An attacker can exploit this issue to reset a user's password. Successful exploits will result in other attacks.
The Secure Password Hashes module for Drupal is prone to a security-bypass vulnerability.
An attacker can exploit this issue to reset a user's password. Successful exploits will result in other attacks.
Exploit / POC
Drupal Secure Password Hashes Module Security Bypass Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Drupal Secure Password Hashes Module Security Bypass Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Drupal Secure Password Hashes Module Security Bypass Vulnerability
References:
References: