Drupal Time Spent Module Multiple Unspecified Input Validation Vulnerabilities
BID:56233
Info
Drupal Time Spent Module Multiple Unspecified Input Validation Vulnerabilities
| Bugtraq ID: | 56233 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-5548 CVE-2012-5549 CVE-2012-5550 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 24 2012 12:00AM |
| Updated: | Nov 23 2012 01:40PM |
| Credit: | Dylan Riordan and Greg Knaddison |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Drupal Time Spent Module Multiple Unspecified Input Validation Vulnerabilities
The Time Spent module for Drupal is prone to unspecified cross-site request forgery, cross-site scripting, and SQL injection vulnerabilities because the application does not properly sanitize user-supplied inputs.
Exploiting these issues could allow an attacker to to perform certain administrative actions and gain unauthorized access to the affected application, steal cookie-based authentication credentials, control how the site is rendered to the user, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The Time Spent module for Drupal is prone to unspecified cross-site request forgery, cross-site scripting, and SQL injection vulnerabilities because the application does not properly sanitize user-supplied inputs.
Exploiting these issues could allow an attacker to to perform certain administrative actions and gain unauthorized access to the affected application, steal cookie-based authentication credentials, control how the site is rendered to the user, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
Drupal Time Spent Module Multiple Unspecified Input Validation Vulnerabilities
Attackers can exploit these issues using browser. To exploit cross-site scripting and cross-site request forgery issues, the attacker must entice an unsuspecting victim to follow a malicious URI.
Attackers can exploit these issues using browser. To exploit cross-site scripting and cross-site request forgery issues, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
Drupal Time Spent Module Multiple Unspecified Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Drupal Time Spent Module Multiple Unspecified Input Validation Vulnerabilities
References:
References:
- Drupal Homepage (Drupal)