Scoutnet vzw
http://forum.scoutnet.be/

[Drupal] Security announcements: Devel - XSS
http://forum.scoutnet.be/viewtopic.php?f=19&t=2047
Pagina 1 van 1

Auteur:  To [ 12 Jan 2008 12:44 ]
Titel:  [Drupal] Security announcements: Devel - XSS

------------SA-2008-001 - DEVEL - CROSS SITE SCRIPTING ------------

* Advisory ID: DRUPAL-SA-2008-001
* Project: Devel (third-party module)
* Version: 5.x
* Date: 2008-January-10
* Security risk: Less critical
* Exploitable from: Remote
* Vulnerability: Cross site scripting

------------DESCRIPTION------------

The devel module contains many useful developer functions, such as a query log and the display of variables. The contents of the variable table is not escaped prior to display. Should an unprivileged user be able to control the contents of a site variable, it would be possible to inject arbitrary HTML and script code into these pages, which may lead to administrator access if certain conditions are met. Learn more about cross site scripting on Wikipedia [ http://en.wikipedia.org/wiki/Cross_site_scripting ].

------------VERSIONS AFFECTED------------

* Devel for Drupal 5.x before Devel 5.x-0.1

Drupal core is not affected. If you do not use the contributed Devel module, there is nothing you need to do.

------------SOLUTION------------

Install the latest version:

* If you use Drupal 5.x upgrade to Devel 5.x-0.1 [ http://drupal.org/node/208526 ].

See also the Devel project page [ http://drupal.org/project/devel ].

------------REPORTED BY------------

Frederic G. MARAND (FGM [ http://drupal.org/user/27985 ]).

------------CONTACT------------

The security contact for Drupal can be reached at security at drupal.org or via the form at [ http://drupal.org/contact ].

Pagina 1 van 1 Alle tijden zijn UTC + 1 uur
Powered by phpBB® Forum Software © phpBB Group
http://www.phpbb.com/