Drupal Search Autocomplete Module Access Security Bypass Vulnerability
BID:54379
Info
Drupal Search Autocomplete Module Access Security Bypass Vulnerability
| Bugtraq ID: | 54379 |
| Class: | Access Validation Error |
| CVE: |
CVE-2012-4471 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2012 12:00AM |
| Updated: | Oct 04 2012 02:10PM |
| Credit: | Reuben Turk |
| Vulnerable: |
Drupal Search Autocomplete 7.x-2.1 Drupal Search Autocomplete 7.x-2.0 |
| Not Vulnerable: | |
Discussion
Drupal Search Autocomplete Module Access Security Bypass Vulnerability
The Search Autocomplete module for Drupal is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized access; this may aid in launching further attacks.
Search Autocomplete 7.x-2.x through versions prior to 7.x-2.4 are vulnerable.
The Search Autocomplete module for Drupal is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized access; this may aid in launching further attacks.
Search Autocomplete 7.x-2.x through versions prior to 7.x-2.4 are vulnerable.
Exploit / POC
Drupal Search Autocomplete Module Access Security Bypass Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
Drupal Search Autocomplete Module Access Security Bypass Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Drupal Search Autocomplete Module Access Security Bypass Vulnerability
References:
References:
- Drupal Homepage (Drupal)