Editor Login | Register
Ekle

Root > World > Security
Drupal Flickr Module Cross-Site Scripting Vulnerabilities - Security - World - Root
CWRedLight
(Date : 03.04.2008 21:33:55)


Drupal Flickr Module Cross-Site Scripting Vulnerabilities
Secunia Advisory: SA29658  
Release Date: 2008-04-03

Critical:
Less critical
Impact: Cross Site Scripting
Where: From remote
Solution Status: Vendor Patch

Software:Drupal Flickr Module 5.x


Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
Some vulnerabilities have been reported in the Flickr module for Drupal, which can be exploited by malicious people to conduct cross-site scripting attacks.

Unspecified input is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user"s browser session in context of an affected site.

The vulnerabilities are reported in versions prior to 5.x-1.3.

Solution:
Update to version 5.x-1.3.
http://drupal.org/node/241943

Provided and/or discovered by:
The vendor credits Kees Cook.

Original Advisory:
http://drupal.org/node/241939












Derecelendir
Kaynak http://secunia.com/advisories/29658/
İçerik İhbarı
Bağlantılar: bilgininefendisi.net

Open Source Document Project AUP&TOS