Twenty Year Anniversary

Drupal FileField Sources 6.x / 7.x Cross Site Scripting

Drupal FileField Sources 6.x / 7.x Cross Site Scripting
Posted Sep 20, 2012
Site drupal.org

Drupal FileField Sources third party module versions 6.x and 7.x suffer from a cross site scripting vulnerability.

tags | advisory, xss
MD5 | 5dfd616ce6f309203bedc1288f92fff6

Drupal FileField Sources 6.x / 7.x Cross Site Scripting

Change Mirror Download
View online: http://drupal.org/node/1789306

* Advisory ID: DRUPAL-SA-CONTRIB-2012-147
* Project: FileField Sources [1] (third-party module)
* Version: 6.x, 7.x
* Date: 2012-September-19
* Security risk: Moderately critical [2]
* Exploitable from: Remote
* Vulnerability: Cross Site Scripting

-------- DESCRIPTION
---------------------------------------------------------

The Drupal FileField module lets you upload files from your computer through
a CCK field. The FileField Sources module expands on this ability by allowing
you to select new or existing files through additional means. The FileField
Sources module contains a persistent cross site scripting (XSS) vulnerability
due to the fact that it fails to sanitize user supplied filenames before
display.

This vulnerability is mitigated by the fact that malicious users must have
the ability to upload files on a field that has the "Reference existing"
source enabled.

CVE: Requested

-------- VERSIONS AFFECTED
---------------------------------------------------

* FileField Sources 6.x-1.x versions prior to 6.x-1.6.
* FileField Sources 7.x-1.x versions prior to 7.x-1.6.

Drupal core is not affected. If you do not use the contributed FileField
Sources [3] module, there is nothing you need to do.

-------- SOLUTION
------------------------------------------------------------

Install the latest version:

* If you use the FileField Sources module for Drupal 6.x, upgrade to
FileField Sources 6.x-1.6 [4]
* If you use the FileField Sources module for Drupal 7.x, upgrade to
FileField Sources 7.x-1.6 [5]

Also see the FileField Sources [6] project page.

-------- REPORTED BY
---------------------------------------------------------

* Disclosed publicly.

-------- FIXED BY
------------------------------------------------------------

* Nathan Haug [7] the module maintainer

-------- COORDINATED BY
------------------------------------------------------

* Greg Knaddison [8] of the Drupal Security Team
* Michael Hess [9] of the Drupal Security Team

-------- CONTACT AND MORE INFORMATION
----------------------------------------

The Drupal security team can be reached at security at drupal.org or via the
contact form at http://drupal.org/contact [10].

Learn more about the Drupal Security team and their policies [11], writing
secure code for Drupal [12], and securing your site [13].


[1] http://drupal.org/project/filefield_sources
[2] http://drupal.org/security-team/risk-levels
[3] http://drupal.org/project/filefield_sources
[4] http://drupal.org/node/1789300
[5] http://drupal.org/node/1789302
[6] http://drupal.org/project/filefield_sources
[7] http://drupal.org/user/35821
[8] http://drupal.org/user/36762
[9] http://drupal.org/user/102818
[10] http://drupal.org/contact
[11] http://drupal.org/security-team
[12] http://drupal.org/writing-secure-code
[13] http://drupal.org/security/secure-configuration

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

Want To Donate?


Bitcoin: 18PFeCVLwpmaBuQqd5xAYZ8bZdvbyEWMmU

File Archive:

July 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    1 Files
  • 2
    Jul 2nd
    26 Files
  • 3
    Jul 3rd
    15 Files
  • 4
    Jul 4th
    11 Files
  • 5
    Jul 5th
    13 Files
  • 6
    Jul 6th
    4 Files
  • 7
    Jul 7th
    4 Files
  • 8
    Jul 8th
    1 Files
  • 9
    Jul 9th
    16 Files
  • 10
    Jul 10th
    15 Files
  • 11
    Jul 11th
    32 Files
  • 12
    Jul 12th
    22 Files
  • 13
    Jul 13th
    15 Files
  • 14
    Jul 14th
    1 Files
  • 15
    Jul 15th
    1 Files
  • 16
    Jul 16th
    21 Files
  • 17
    Jul 17th
    15 Files
  • 18
    Jul 18th
    15 Files
  • 19
    Jul 19th
    3 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close