exploit the possibilities

Drupal Campaign Monitor 6.x Cross Site Scripting

Drupal Campaign Monitor 6.x Cross Site Scripting
Posted Jul 19, 2012
Site drupal.org

Drupal third party module Campaign Monitor versions 6.x-2.x prior to 6.x-2.5 suffer from a cross site scripting vulnerability.

tags | advisory, xss
MD5 | 29628b652ae555f8d44729bbbd484cdb

Drupal Campaign Monitor 6.x Cross Site Scripting

Change Mirror Download
View online: http://drupal.org/node/1691446

* Advisory ID: SA-CONTRIB-2012-114
* Project: Campaign Monitor [1] (third-party module)
* Version: 6.x
* Date: 2012-July-18
* Security risk: Moderately critical [2]
* Exploitable from: Remote
* Vulnerability: Cross Site Scripting

-------- DESCRIPTION
---------------------------------------------------------

This module enables you to integrate Campaign Monitor into Drupal so you can
give users the ability to subscribe and unsubscribe for your Campaign Monitor
lists.

The module doesn't sufficiently validate strings entered in the
administration interface.
This vulnerability is mitigated by the fact that an attacker must have a role
with the permission "administer campaignmonitor".

CVE: Requested

-------- VERSIONS AFFECTED
---------------------------------------------------

* Campaign Monitor 6.x-2.x versions prior to 6.x-2.5

Drupal core is not affected. If you do not use the contributed Campaign
Monitor [3] module, there is nothing you need to do.

-------- SOLUTION
------------------------------------------------------------

Install the latest version:

* If you use the Campaign Monitor module for Drupal 6.x, upgrade to Campaign
Monitor 6.x-2.5 [4]

Also see the Campaign Monitor [5] project page.

-------- REPORTED BY
---------------------------------------------------------

* Andrey Tretyakov [6]

-------- FIXED BY
------------------------------------------------------------

* Jesper Kristensen [7] the module maintainer

-------- COORDINATED BY
------------------------------------------------------

* Greg Knaddison [8] of the Drupal Security Team

-------- CONTACT AND MORE INFORMATION
----------------------------------------

The Drupal security team can be reached at security at drupal.org or via the
contact form at http://drupal.org/contact [9].

Learn more about the Drupal Security team and their policies [10], writing
secure code for Drupal [11], and securing your site [12].


[1] http://drupal.org/project/campaignmonitor
[2] http://drupal.org/security-team/risk-levels
[3] http://drupal.org/project/campaignmonitor
[4] http://drupal.org/node/1689790
[5] http://drupal.org/project/campaignmonitor
[6] http://drupal.org/user/169459
[7] http://drupal.org/user/697210
[8] http://drupal.org/user/36762
[9] http://drupal.org/contact
[10] http://drupal.org/security-team
[11] http://drupal.org/writing-secure-code
[12] http://drupal.org/security/secure-configuration

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2019

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    16 Files
  • 2
    May 2nd
    8 Files
  • 3
    May 3rd
    8 Files
  • 4
    May 4th
    2 Files
  • 5
    May 5th
    1 Files
  • 6
    May 6th
    15 Files
  • 7
    May 7th
    22 Files
  • 8
    May 8th
    16 Files
  • 9
    May 9th
    17 Files
  • 10
    May 10th
    16 Files
  • 11
    May 11th
    3 Files
  • 12
    May 12th
    4 Files
  • 13
    May 13th
    25 Files
  • 14
    May 14th
    24 Files
  • 15
    May 15th
    78 Files
  • 16
    May 16th
    16 Files
  • 17
    May 17th
    16 Files
  • 18
    May 18th
    2 Files
  • 19
    May 19th
    1 Files
  • 20
    May 20th
    11 Files
  • 21
    May 21st
    21 Files
  • 22
    May 22nd
    20 Files
  • 23
    May 23rd
    36 Files
  • 24
    May 24th
    2 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2019 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close