Drupal Password Policy Module Security Vulnerability
BID:67568
Info
Drupal Password Policy Module Security Vulnerability
| Bugtraq ID: | 67568 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2014 12:00AM |
| Updated: | May 21 2014 12:00AM |
| Credit: | AohRveTPV |
| Vulnerable: |
Drupal Password Policy 7.x-1.5 Drupal Password Policy 7.x-1.4 Drupal Password Policy 7.x-1.3 Drupal Password Policy 7.x-1.0 |
| Not Vulnerable: |
Drupal Password Policy 7.x-1.6 |
Discussion
Drupal Password Policy Module Security Vulnerability
Password Policy module is prone to a security vulnerability because of improper implementation of the history constraint feature.
An attacker may exploit this issue to perform unauthorized actions in the context of the application. This may aid in other attacks.
Password policy 7.x-1.x versions prior to 7.x-1.6 are vulnerable.
Password Policy module is prone to a security vulnerability because of improper implementation of the history constraint feature.
An attacker may exploit this issue to perform unauthorized actions in the context of the application. This may aid in other attacks.
Password policy 7.x-1.x versions prior to 7.x-1.6 are vulnerable.
Exploit / POC
Drupal Password Policy Module Security Vulnerability
An attacker can exploit this issue by readily available tools.
An attacker can exploit this issue by readily available tools.