Spider Video Player Module Arbitrary File Deletion and Cross Site Request Forgery Vulnerabilities
BID:72817
Info
Spider Video Player Module Arbitrary File Deletion and Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 72817 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-4351 CVE-2015-4352 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2015 12:00AM |
| Updated: | Jul 15 2015 12:32AM |
| Credit: | Pere Orga of the Drupal Security Team |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Spider Video Player Module Arbitrary File Deletion and Cross Site Request Forgery Vulnerabilities
The Spider Video Player module for Drupal is prone to multiple cross-site request-forgery vulnerabilities and an arbitrary-file-deletion vulnerability.
Attackers may exploit these issues to perform unauthorized actions by enticing a logged-in user to visit a malicious site and delete arbitrary files in the context of the application; this may aid in launching further attacks.
Spider Video Player 6.x and 7.x are vulnerable; other versions may also be affected.
The Spider Video Player module for Drupal is prone to multiple cross-site request-forgery vulnerabilities and an arbitrary-file-deletion vulnerability.
Attackers may exploit these issues to perform unauthorized actions by enticing a logged-in user to visit a malicious site and delete arbitrary files in the context of the application; this may aid in launching further attacks.
Spider Video Player 6.x and 7.x are vulnerable; other versions may also be affected.
Exploit / POC
Spider Video Player Module Arbitrary File Deletion and Cross Site Request Forgery Vulnerabilities
Attackers can use a browser to exploit the arbitrary-file-deletion issue. To exploit the cross-site request-forgery issue, attackers must entice an unsuspecting victim to follow a malicious URI.
Attackers can use a browser to exploit the arbitrary-file-deletion issue. To exploit the cross-site request-forgery issue, attackers must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
Spider Video Player Module Arbitrary File Deletion and Cross Site Request Forgery Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Spider Video Player Module Arbitrary File Deletion and Cross Site Request Forgery Vulnerabilities
References:
References:
- Drupal Homepage (Drupal)