Multiple Drupal Modules HTML Injection Vulnerability
BID:56540
Info
Multiple Drupal Modules HTML Injection Vulnerability
| Bugtraq ID: | 56540 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2012 12:00AM |
| Updated: | Nov 14 2012 12:00AM |
| Credit: | Jimmy Axenhus |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Multiple Drupal Modules HTML Injection Vulnerability
Multiple Drupal modules are prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied text.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
The following modules and versions are affected:
Smiley 6.x-1.x versions prior to 6.x-1.1
Smileys 6.x-1.x versions prior to 6.x-1.1
Multiple Drupal modules are prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied text.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
The following modules and versions are affected:
Smiley 6.x-1.x versions prior to 6.x-1.1
Smileys 6.x-1.x versions prior to 6.x-1.1
Exploit / POC
Multiple Drupal Modules HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Multiple Drupal Modules HTML Injection Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.