Drupal News Message HTML Injection Vulnerability
BID:5801
Info
Drupal News Message HTML Injection Vulnerability
| Bugtraq ID: | 5801 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1806 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2002 12:00AM |
| Updated: | Apr 12 2007 07:51PM |
| Credit: | Discovery of this vulnerability credited to [email protected]. |
| Vulnerable: |
Drupal Drupal 4.0 .0 |
| Not Vulnerable: |
Drupal Drupal 4.6.11 |
Discussion
Drupal News Message HTML Injection Vulnerability
Problems with Drupal could allow an attacker to execute arbitrary script code in a vulnerable client.
Drupal fails to sufficiently filter potentially malicious HTML code from news posts. As a result, when a user views a news posting that contains malicious HTML code, the code contained in the posted message would be executed in their browser. This will occur in the context of the site running the Drupal software.
Problems with Drupal could allow an attacker to execute arbitrary script code in a vulnerable client.
Drupal fails to sufficiently filter potentially malicious HTML code from news posts. As a result, when a user views a news posting that contains malicious HTML code, the code contained in the posted message would be executed in their browser. This will occur in the context of the site running the Drupal software.
Exploit / POC
Drupal News Message HTML Injection Vulnerability
The following proof of concept was submitted.
<IMG SRC="javascript:alert('unsecure')">
The following proof of concept was submitted.
<IMG SRC="javascript:alert('unsecure')">
Solution / Fix
Drupal News Message HTML Injection Vulnerability
Solution:
The vendor recommends updating to the latest release of Drupal.
Solution:
The vendor recommends updating to the latest release of Drupal.