Scoutnet vzw
http://forum.scoutnet.be/

[Drupal] Security announcements: Tinytax - XSS
http://forum.scoutnet.be/viewtopic.php?f=19&t=2149
Pagina 1 van 1

Auteur:  To [ 03 Jul 2008 17:34 ]
Titel:  [Drupal] Security announcements: Tinytax - XSS

------------SA-2008-042 - TINYTAX - CROSS SITE SCRIPTING ------------

* Advisory ID: DRUPAL-SA-2008-042
* Project: Tinytax taxonomy block (third-party module)
* Version: 5.x
* Date: 2008-July-2
* Security risk: Moderately critical
* Exploitable from: Remote
* Vulnerability: Cross site scripting

------------DESCRIPTION------------

The Tinytax taxonomy block displays a vocabulary as a tree within a block.

The module displays certain values without appropriate filtering. Malicious users with the permission to create taxonomy terms are able to exploit this issue and insert arbitrary HTML and script code into pages. Such a cross site scripting attack [ http://en.wikipedia.org/wiki/Cross-site_scripting ] (XSS) may lead to the malicious user gaining administrator access.

------------VERSIONS AFFECTED------------

* Tinytax taxonomy block for Drupal 5.x prior to 5.x-1.10-1.

Drupal core is not affected. If you do not use the contributed Tinytax taxonomy block module, there is nothing you need to do.

------------SOLUTION------------

Install the latest version:

* Tinytax taxonomy block 5.x-1.10 [ http://drupal.org/node/277682 ].

See also the Tinytax taxonomy block project page [ http://drupal.org/project/tinytax ].

------------REPORTED BY------------

* The cross site scripting issue was reported by the module maintainer, Simon Rycroft [ http://drupal.org/user/151544 ].

------------CONTACT------------

The security contact for Drupal can be reached at security at drupal.org or via the form at [ http://drupal.org/contact ] and by selecting the security issues category.

Pagina 1 van 1 Alle tijden zijn UTC + 1 uur
Powered by phpBB® Forum Software © phpBB Group
http://www.phpbb.com/