what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

CurvyCorners Cross Site Scripting

CurvyCorners Cross Site Scripting
Posted Jan 24, 2013
Authored by Stephan Rickauer | Site csnc.ch

CurvyCorners module versions 6.x-1.x and 7.x-1.x suffer from a cross site scripting vulnerability.

tags | advisory, xss
advisories | CVE-2013-1393
SHA-256 | d7fcabd2dc84c5a5de2f1ab425fd8512a1b54d1044e9469a9dfdc728a0128de3

CurvyCorners Cross Site Scripting

Change Mirror Download
#############################################################
#
# COMPASS SECURITY ADVISORY http://www.csnc.ch/
#
#############################################################
#
# CVE ID : CVE-2013-1393
# CSNC ID: CSNC-2013-002
# Product: Drupal CurvyCorners
# Vendor: Drupal
# Subject: Cross-site Scripting - XSS
# Risk: High
# Effect: Remotely exploitable
# Author: Stephan Rickauer (stephan.rickauer _at_ csnc.ch)
# Date: January 23rd 2013
#
#############################################################


Introduction:
-------------
Compass Security discovered a web application security flaw in the
CurvyCorners module of the Drupal CMS.


Vulnerable:
-----------
All CurvyCorners 6.x-1.x versions.
All CurvyCorners 7.x-1.x versions.


Not vulnerable:
---------------
unknown


Fix/Patches:
------------
If you use the CurvyCorners module, uninstall the module - there is no
patch available to fix this issue. The module is no longer supported.


Description:
------------
The CurvyCorners module enables you to create rounded corners on HTML
block elements. The module doesn't sufficiently filter user entered
text when being displayed. This vulnerability is mitigated by the fact
that an attacker must have a role with the permission "administer
curvycorners". Exploiting this vulnerability will lead to so-called
cross-site scripting (XSS) and allows the impersonation of logged-in
Drupal users.


Milestones:
-----------
December 14th 2012 Vulnerability discovered
December 14th 2012 Vendor contact established
December 14th 2012 Vendor acknowledged issue
January 17th 2013 CVE ID assigned by MITRE
January 23rd 2013 Public release of advisory by vendor


References:
-----------
XSS reference:
http://en.wikipedia.org/wiki/Cross-site_scripting
Cross-site scripting (XSS) is a type of computer security vulnerability
typically found in web applications which allow code injection by
malicious web users into the web pages viewed by other users. Examples
of such code include HTML code and client-side scripts. An exploited
cross-site scripting vulnerability can be used by attackers to bypass
access controls such as the same origin policy. Recently,
vulnerabilities of this kind have been exploited to craft powerful
phishing attacks and browser exploits.

Drupal SA-CONTRIB-2013-008:
http://drupal.org/node/1896718


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close