what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Drupal Custom Publishing Options 6.x XSS

Drupal Custom Publishing Options 6.x XSS
Posted Aug 15, 2012
Authored by Justin C. Klein Keane

Drupal version 6.22 with Custom Publishing Options version 6.x-1.4 suffers from a cross site scripting vulnerability. Proof of concept information included.

tags | exploit, xss, proof of concept
SHA-256 | 48dd91f8b89ca979ca8e11af83723a4ee087f9e15fcaa581b8d6f6470708cf67

Drupal Custom Publishing Options 6.x XSS

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Vulnerability Report

Reported: January 3, 2012
Author: Justin C. Klein Keane <justin@madirish.net>

Description of Vulnerability:
- -----------------------------
Drupal (http://drupal.org) is a robust content management system (CMS)
written in PHP and MySQL. The Drupal Custom Publishing Options module
(https://drupal.org/project/custom_pub) contains a persistent cross
site scripting (XSS) vulnerability due to the fact that it fails to
sanitize format names before display.

Systems affected:
- -----------------
Drupal 6.22 with Custom Publishing Options 6.x-1.4 was tested and
shown to be vulnerable

Impact
- ------
User could inject arbitrary scripts into pages affecting site users.
This could result in administrative account compromise leading to web
server process compromise.

Mitigating factors:
- -------------------
In order to execute arbitrary script injection malicious users must
have 'Administer nodes' permission.

Proof of Concept:
- -----------------
1. Install and enable the Custom Publishing Options module
2. Add a new label at ?q=admin/content/custom_pub inserting arbitrary
HTML in the 'Publishing label' field.
3. Save the label to view the rendered script or view it on the
create content page for the appropriate content type.

Vendor response:
- ---------------
Upgrade to the latest version

- --
Justin C. Klein Keane
http://www.MadIrish.net

The PGP signature on this email can be verified using the public key at
http://www.madirish.net/gpgkey
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iPwEAQECAAYFAlAr7tQACgkQkSlsbLsN1gA+ogb/drMm08BCFHlfKg21hVHtoGjN
bKLX26wErcLfvsIlwfPvCQx3cme8BNoUA7pCyjmYAIQAZBnAlNvXA6fxz4aLuED5
I8zkwWFOYLKHXlsXYI2hnPuf4AVUFE3wPptqSTqONzE3GIWVyIolIOwmYxT1mi8P
7s3bWG/MpKE0owNDYzNkM5qjBULIgMzyX1SIIGkqde8UqZrIJLk0AbKeDtNLeJ5p
yb2WA8eIbkDUTPEPUpAu4fU43ki+dh0BN1b3Xqalrtel12ln1k62jORVqh07TGe/
wj9F9msw4R1wqHEZFlk=
=B/fi
-----END PGP SIGNATURE-----


Login or Register to add favorites

File Archive:

March 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    13 Files
  • 3
    Mar 3rd
    15 Files
  • 4
    Mar 4th
    0 Files
  • 5
    Mar 5th
    0 Files
  • 6
    Mar 6th
    16 Files
  • 7
    Mar 7th
    31 Files
  • 8
    Mar 8th
    16 Files
  • 9
    Mar 9th
    13 Files
  • 10
    Mar 10th
    9 Files
  • 11
    Mar 11th
    0 Files
  • 12
    Mar 12th
    0 Files
  • 13
    Mar 13th
    10 Files
  • 14
    Mar 14th
    6 Files
  • 15
    Mar 15th
    17 Files
  • 16
    Mar 16th
    22 Files
  • 17
    Mar 17th
    13 Files
  • 18
    Mar 18th
    0 Files
  • 19
    Mar 19th
    0 Files
  • 20
    Mar 20th
    16 Files
  • 21
    Mar 21st
    13 Files
  • 22
    Mar 22nd
    5 Files
  • 23
    Mar 23rd
    6 Files
  • 24
    Mar 24th
    47 Files
  • 25
    Mar 25th
    0 Files
  • 26
    Mar 26th
    0 Files
  • 27
    Mar 27th
    50 Files
  • 28
    Mar 28th
    42 Files
  • 29
    Mar 29th
    7 Files
  • 30
    Mar 30th
    31 Files
  • 31
    Mar 31st
    15 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close