Drupal Views Module SQL Injection Vulnerability
BID:50500
Info
Drupal Views Module SQL Injection Vulnerability
| Bugtraq ID: | 50500 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-4113 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 02 2011 12:00AM |
| Updated: | Apr 13 2015 09:31PM |
| Credit: | Olli Vesslin |
| Vulnerable: |
Drupal Views 6.x-2.9 Drupal Views 6.x-2.8 Drupal Views 6.x-2.6 Drupal Views 6.x-2.5 Drupal Views 6.x-2.2 Drupal Views 6.X-2.12 Drupal Views 6.X-2.11 Drupal Views 6.X-2.10 Drupal Views 6.X-2.1 Drupal Views 6.x-2.0 |
| Not Vulnerable: |
Drupal Views 6.X.2.14 Drupal Views 6.X.2.13 |
Discussion
Drupal Views Module SQL Injection Vulnerability
The Views module for Drupal is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Views 6.x-2.13 are vulnerable.
The Views module for Drupal is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Views 6.x-2.13 are vulnerable.
Exploit / POC
Drupal Views Module SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Drupal Views Module SQL Injection Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
Drupal Views Module SQL Injection Vulnerability
References:
References:
- Drupal Homepage (Drupal)
- Drupal Views Module Homepage (Drupal)
- SA-CONTRIB-2011-052 - Views SQL Injection (Drupal)