Drupal OG Feature Local Task Menu Item Security Bypass Vulnerability
BID:49970
Info
Drupal OG Feature Local Task Menu Item Security Bypass Vulnerability
| Bugtraq ID: | 49970 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 05 2011 12:00AM |
| Updated: | Oct 05 2011 12:00AM |
| Credit: | Imad Nabli |
| Vulnerable: |
Drupal OG Feature 6.X-1.1 |
| Not Vulnerable: |
Drupal OG Feature 6.X-1.2 |
Discussion
Drupal OG Feature Local Task Menu Item Security Bypass Vulnerability
The OG Feature module for Drupal is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions and gain access to pages that contain local tasks. Successful exploits will compromise the affected application.
OG Feature versions 6.x-1.x prior to 6.x-1.2 are vulnerable.
The OG Feature module for Drupal is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions and gain access to pages that contain local tasks. Successful exploits will compromise the affected application.
OG Feature versions 6.x-1.x prior to 6.x-1.2 are vulnerable.
Exploit / POC
Drupal OG Feature Local Task Menu Item Security Bypass Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Drupal OG Feature Local Task Menu Item Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.