Drupal Email Field Module Cross Site Scripting and Security Bypass Vulnerabilities
BID:56728
Info
Drupal Email Field Module Cross Site Scripting and Security Bypass Vulnerabilities
| Bugtraq ID: | 56728 |
| Class: | Unknown |
| CVE: |
CVE-2012-5587 CVE-2012-5588 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2012 12:00AM |
| Updated: | Nov 28 2012 12:00AM |
| Credit: | Fox (hefox) |
| Vulnerable: |
Drupal Email Field 6.X-1.2 |
| Not Vulnerable: |
Drupal Email Field 6.X-1.3 |
Discussion
Drupal Email Field Module Cross Site Scripting and Security Bypass Vulnerabilities
The Email Field module for Drupal is prone to a cross-site scripting vulnerability and a security-bypass vulnerability.
An attacker can exploit the cross-site scripting issue to execute arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials.
The attacker can exploit the security bypass issue to bypass security restrictions and obtain sensitive information, or perform unauthorized actions; this may aid in launching further attacks.
Email Field 6.x-1.x versions prior to 6.x-1.3 are vulnerable.
The Email Field module for Drupal is prone to a cross-site scripting vulnerability and a security-bypass vulnerability.
An attacker can exploit the cross-site scripting issue to execute arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials.
The attacker can exploit the security bypass issue to bypass security restrictions and obtain sensitive information, or perform unauthorized actions; this may aid in launching further attacks.
Email Field 6.x-1.x versions prior to 6.x-1.3 are vulnerable.
References
Drupal Email Field Module Cross Site Scripting and Security Bypass Vulnerabilities
References:
References: