Drupal Password Policy Module Password Hash Information Disclosure Vulnerability
BID:56350
Info
Drupal Password Policy Module Password Hash Information Disclosure Vulnerability
| Bugtraq ID: | 56350 |
| Class: | Design Error |
| CVE: |
CVE-2012-5552 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2012 12:00AM |
| Updated: | Nov 23 2012 04:20PM |
| Credit: | Alexis Wilke |
| Vulnerable: |
Drupal Password Policy 6.X-1.X |
| Not Vulnerable: | |
Discussion
Drupal Password Policy Module Password Hash Information Disclosure Vulnerability
The Password Policy module for Drupal is prone to an information-disclosure vulnerability.
An attacker can exploit this vulnerability to obtain sensitive information through man-in-the-middle attacks that may lead to further attacks.
The following versions are vulnerable:
Password Policy 6.x-1.x versions prior to 6.x-1.5 are vulnerable.
Password Policy 7.x-1.x versions prior to 7.x-1.3 are vulnerable.
The Password Policy module for Drupal is prone to an information-disclosure vulnerability.
An attacker can exploit this vulnerability to obtain sensitive information through man-in-the-middle attacks that may lead to further attacks.
The following versions are vulnerable:
Password Policy 6.x-1.x versions prior to 6.x-1.5 are vulnerable.
Password Policy 7.x-1.x versions prior to 7.x-1.3 are vulnerable.
Exploit / POC
Drupal Password Policy Module Password Hash Information Disclosure Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Drupal Password Policy Module Password Hash Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Drupal Password Policy Module Password Hash Information Disclosure Vulnerability
References:
References:
- Drupal Homepage (Drupal)