exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Drupal Embedded Media Field Cross Site Scripting

Drupal Embedded Media Field Cross Site Scripting
Posted Dec 9, 2010
Authored by Justin C. Klein Keane

Drupal 6.19 with Embedded Media Field 6.x-1.25 and CCK 6.x-2.8 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 3e4fc930adc768a98c38cadb8899485067256c5adccd77f043a3393b44404281

Drupal Embedded Media Field Cross Site Scripting

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Details of this disclosure are also available at
http://www.madirish.net/?article=472


Description of Vulnerability:
- -----------------------------
Drupal (http://drupal.org) is a robust content management system (CMS)
written in PHP and MySQL. The Drupal Embedded Media Field module
(http://drupal.org/project/emfield) "will create fields for content
types that can be used to display video, image, and audio files from
various third party providers" Unfortunately the Embedded Media Field
module contains an arbitrary HTML injection vulnerability (also known as
cross site scripting, or XSS) due to the fact that it fails to sanitize
user supplied audio file paths and custom embed code.

Systems affected:
- -----------------
Drupal 6.19 with Embedded Media Field 6.x-1.25 and CCK 6.x-2.8 was
tested and shown to be vulnerable

Impact
- ------
Users could inject arbitrary scripts into pages affecting other site
users. This could result in administrative account compromise leading
to web server process compromise. A more likely scenario would be for
an attacker to inject hidden content (such as iframes, applets, or
embedded objects) that would attack client browsers in an attempt to
compromise site users' machines. This vulnerability could also be used
to launch cross site request forgery (XSRF) attacks against the site
that could have other unexpected consequences.

Mitigating factors:
- -------------------
In order to exploit this vulnerability the attacker must have the
ability to edit content of a content type with an embedded media field.

Proof of concept:
- -----------------
1. Install Drupal 6-19, CCK module, and Embedded Media Field module
version 6.x-1.25
2. Enable the Content, Embedded Media Field, Embedded Audio Field
modules from ?q=/admin/build/modules
3. Alter the default 'Story' content type at
?q=admin/content/node-type/story/fields
4. Add a 'New Field' in the form at the bottom of this page with the
label 'audio' the field name 'field_audio' the type 'Embedded Audio' and
the form element '3rd Party Aduio' then click the 'Save' button
5. Configure the new video field from
?q=admin/content/node-type/story/fields/field_video
6. Select all content providers for convenience and click 'Save field
settings' button at the bottom of the form
7. Create a new piece of story content from ?q=node/add/story entering
arbitrary values.
8. Enter "'/><script>alert('xss');</script><embed
onshow='alert("foo");'
src='http://traffic.libsyn.com/pauldotcom/PaulDotCom-SW-217pt2.mp3" in
the 'audio:' text field
9. Click the 'Save' and observe the rendered JavaScript alert whenever
the node is displayed

Patch:
- ------------------------------------------
Applying the following patch mitigates this issue in version 6.x-1.25

- --- emfield/contrib/emaudio/providers/custom_url.inc 2009-06-26
14:31:00.000000000 -0400
+++ emfield/contrib/emaudio/providers/custom_url.inc 2010-11-05
15:17:08.000000000 -0400
@@ -110,6 +110,7 @@ function emaudio_custom_url_rss($item, $
}

function theme_emaudio_custom_url_flash($url = NULL, $width = 0,
$height = 0, $field = NULL, $data = array(), $node = NULL, $autoplay =
FALSE) {
+ $url=str_replace("'", '', $url); //this should be a URL validator
instead
// Display the audio using Flowplayer if it's available.
if (module_exists('flowplayer')) {
$config = array(

Vendor Response
- ---------------
http://drupal.org/node/992924


- --
Justin Klein Keane
http://www.MadIrish.net

The digital signature on this message can be confirmed using
the public key at http://www.madirish.net/gpgkey
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/

iPwEAQECAAYFAk0BFaEACgkQkSlsbLsN1gAcRAb/UI8b0S22tSsvwfimbi9mQSpr
wkKheh8Z/b+GGrYSYMh94acQlHJsnIMwRxVK1VJrlYm/IJd4lYJ/B5ZAlRwPryqx
K7POTeJSJ0zlOLaMkO6Gdblu0p8KmJEIglR8nU+R0+//wfBV4wmG5DuuV3k0v48l
1FC3rdmsBwup17wI7gXR5qc+Ck82p2oB90tiJHKwsfS55DTN3dfMFzL41E04GlsA
rtf950j8Tutp4MsvRK+f5yIOiyyo/DzJWBa1CdZ5FjryBmuiMg1ianpCO9RD6DwH
dqFte4LY8hztccAPXeI=
=bVtj
-----END PGP SIGNATURE-----

Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close