Drupal Hotblocks Module HTML Injection and Denial of Service Vulnerabilities
BID:55038
Info
Drupal Hotblocks Module HTML Injection and Denial of Service Vulnerabilities
| Bugtraq ID: | 55038 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2012 12:00AM |
| Updated: | Aug 15 2012 12:00AM |
| Credit: | Justin C. Klein Keane |
| Vulnerable: |
Drupal HotBlocks 6.x-1.6 Drupal HotBlocks 6.X-1.5 Drupal HotBlocks 6.X-1.4 |
| Not Vulnerable: | |
Discussion
Drupal Hotblocks Module HTML Injection and Denial of Service Vulnerabilities
Hotblocks is prone to HTML-injection and denial-of-service vulnerabilities.
Attackers can exploit these issues to cause denial-of-service conditions or to execute attacker-supplied HTML or JavaScript code in the context of the affected site, potentially allowing them to steal cookie-based authentication credentials and to control how the site is rendered to the user.
Hotblocks versions prior to 6.x-1.8 are vulnerable.
Hotblocks is prone to HTML-injection and denial-of-service vulnerabilities.
Attackers can exploit these issues to cause denial-of-service conditions or to execute attacker-supplied HTML or JavaScript code in the context of the affected site, potentially allowing them to steal cookie-based authentication credentials and to control how the site is rendered to the user.
Hotblocks versions prior to 6.x-1.8 are vulnerable.
Exploit / POC
Drupal Hotblocks Module HTML Injection and Denial of Service Vulnerabilities
An attacker can exploit these issues using a browser.
An attacker can exploit these issues using a browser.
Solution / Fix
Drupal Hotblocks Module HTML Injection and Denial of Service Vulnerabilities
Solution:
Updates are available; please see the references for details.
Solution:
Updates are available; please see the references for details.
References
Drupal Hotblocks Module HTML Injection and Denial of Service Vulnerabilities
References:
References:
- HotBlocks Homepage (HotBlocks)