Drupal Core CSS Selectors Remote Security Vulnerability
BID:62174
Info
Drupal Core CSS Selectors Remote Security Vulnerability
| Bugtraq ID: | 62174 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 04 2013 12:00AM |
| Updated: | Sep 04 2013 12:00AM |
| Credit: | Aaron Weiss |
| Vulnerable: |
Drupal Drupal 7.6 Drupal Drupal 7.5 Drupal Drupal 7.4 Drupal Drupal 7.3 Drupal Drupal 7.20 Drupal Drupal 7.2 Drupal Drupal 7.19 Drupal Drupal 7.18 Drupal Drupal 7.17 Drupal Drupal 7.16 Drupal Drupal 7.15 Drupal Drupal 7.14 Drupal Drupal 7.13 Drupal Drupal 7.12 Drupal Drupal 7.11 Drupal Drupal 7.10 Drupal Drupal 7.1 Drupal Drupal 7.0 Dev Drupal Drupal 7.0 Alpha7 Drupal Drupal 7.0 Alpha6 Drupal Drupal 7.0 Alpha5 Drupal Drupal 7.0 Alpha4 Drupal Drupal 7.0 Alpha3 Drupal Drupal 7.0 Alpha2 Drupal Drupal 7.0 Alpha1 Drupal Drupal 7.0 Drupal Drupal 6.9 Drupal Drupal 6.8 Drupal Drupal 6.7 Drupal Drupal 6.6 Drupal Drupal 6.5 Drupal Drupal 6.4 Drupal Drupal 6.3 Drupal Drupal 6.28 Drupal Drupal 6.27 Drupal Drupal 6.26 Drupal Drupal 6.23 Drupal Drupal 6.22 Drupal Drupal 6.22 Drupal Drupal 6.2 Drupal Drupal 6.18 Drupal Drupal 6.17 Drupal Drupal 6.16 Drupal Drupal 6.15 Drupal Drupal 6.14 Drupal Drupal 6.13 Drupal Drupal 6.12 Drupal Drupal 6.11 Drupal Drupal 6.10 Drupal Drupal 6.1 Drupal Drupal 6.0 Rc4 Drupal Drupal 6.0 Rc3 Drupal Drupal 6.0 Rc2 Drupal Drupal 6.0 Rc1 Drupal Drupal 6.0 Dev Drupal Drupal 6.0 Beta4 Drupal Drupal 6.0 Beta3 Drupal Drupal 6.0 Beta2 Drupal Drupal 6.0 Beta1 Drupal Drupal 6.0 |
| Not Vulnerable: | |
Discussion
Drupal Core CSS Selectors Remote Security Vulnerability
Drupal is prone to a remote security vulnerability.
Attackers can leverage this issue to insert hidden links in comments. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
Drupal versions 6.x and 7.x are vulnerable.
Drupal is prone to a remote security vulnerability.
Attackers can leverage this issue to insert hidden links in comments. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
Drupal versions 6.x and 7.x are vulnerable.
Exploit / POC
Drupal Core CSS Selectors Remote Security Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Drupal Core CSS Selectors Remote Security Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].