Drupal Multiple Remote Security Vulnerabilities
BID:68706
Info
Drupal Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 68706 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-5019 CVE-2014-5020 CVE-2014-5021 CVE-2014-5022 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2014 12:00AM |
| Updated: | May 07 2015 05:18PM |
| Credit: | Régis Leroy, Ivan Ch, Károly Négyesi, and mani22test. |
| Vulnerable: |
Drupal Drupal 7.6 Drupal Drupal 7.5 Drupal Drupal 7.4 Drupal Drupal 7.3 Drupal Drupal 7.2 Drupal Drupal 7.14 Drupal Drupal 7.13 Drupal Drupal 7.12 Drupal Drupal 7.11 Drupal Drupal 7.10 Drupal Drupal 7.1 Drupal Drupal 7.0 Drupal Drupal 6.9 Drupal Drupal 6.8 Drupal Drupal 6.7 Drupal Drupal 6.6 Drupal Drupal 6.5 Drupal Drupal 6.4 Drupal Drupal 6.3 Drupal Drupal 6.23 Drupal Drupal 6.22 Drupal Drupal 6.2 Drupal Drupal 6.18 Drupal Drupal 6.17 Drupal Drupal 6.16 Drupal Drupal 6.15 Drupal Drupal 6.14 Drupal Drupal 6.13 Drupal Drupal 6.12 Drupal Drupal 6.11 Drupal Drupal 6.10 Drupal Drupal 6.1 Drupal Drupal 6.0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
Drupal Multiple Remote Security Vulnerabilities
Drupal is prone to denial-of-service, access-bypass, and multiple cross-site scripting vulnerabilities; fixes are available.
An attacker can exploit these issues to execute arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials, cause a denial-of-service condition and bypass security restrictions, or perform unauthorized actions; this may aid in launching further attacks.
Following versions are vulnerable:
Drupal 6.x prior to 6.32
Drupal 7.x prior to 7.29
Drupal is prone to denial-of-service, access-bypass, and multiple cross-site scripting vulnerabilities; fixes are available.
An attacker can exploit these issues to execute arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials, cause a denial-of-service condition and bypass security restrictions, or perform unauthorized actions; this may aid in launching further attacks.
Following versions are vulnerable:
Drupal 6.x prior to 6.32
Drupal 7.x prior to 7.29
Exploit / POC
Drupal Multiple Remote Security Vulnerabilities
Attackers can use a browser to exploit the access-bypass and denial-of-service issues. To exploit cross-site scripting vulnerability attackers must trick an unsuspecting victim into following a malicious URI.
Attackers can use a browser to exploit the access-bypass and denial-of-service issues. To exploit cross-site scripting vulnerability attackers must trick an unsuspecting victim into following a malicious URI.
Solution / Fix
Drupal Multiple Remote Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.