[Imc-drupal-dev] [Fwd: [Security announcements] XSS Vulnerability in user module]
Dan Rossi
cat-list at electroteque.org
Wed Aug 2 18:00:30 PDT 2006
This kind of stuff can be prevented using mod_security
http://www.modsecurity.org/
Its pretty good at keeping any kind of apache DOS attack at bay.
Cameron Gregg wrote:
>
> ------------------------------------------------------------------------
>
> Subject:
> [Security announcements] XSS Vulnerability in user module
> From:
> "Drupal Security Team" <security at drupal.org>
> Date:
> Wed, 2 Aug 2006 19:27:49 +0000 (UTC)
> To:
> cam at earthanarchy.org
>
> To:
> cam at earthanarchy.org
>
>
>
> ------------XSS VULNERABILITY IN USER MODULE------------
>
> * Advisory ID: DRUPAL-SA-2006-011
>
> * Project: Drupal core
>
> * Date: 2006-Aug-2
>
> * Security risk: less critical
>
> * Impact: Drupal core
>
> * Exploitable from: remote
>
> * Vulnerability: cross-site scripting
>
> ------------DESCRIPTION------------
>
> A malicious user can execute a cross site scripting attack by enticing
> someone
> to visit a Drupal site via a specially crafted link.
> ------------VERSIONS AFFECTED------------
>
> * Drupal 4.6.x versions before Drupal 4.6.9
>
> * Drupal 4.7.x versions before Drupal 4.7.3
>
> ------------SOLUTION------------
>
> * If you are running Drupal 4.6.x then upgrade to Drupal 4.6.9
> [http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.6.9.tar.gz].
>
> * If you are running Drupal 4.7.x then upgrade to Drupal 4.7.3
> [http://ftp.osuosl.org/pub/drupal/files/projects/drupal-4.7.3.tar.gz].
>
> * To patch Drupal 4.6.8 use
> http://drupal.org/files/sa-2006-011/4.6.8.patch
> [http://drupal.org//files/sa-2006-011/4.6.8.patch].
>
> * To patch Drupal 4.7.2 use
> http://drupal.org/files/sa-2006-011/4.7.2.patch
> [http://drupal.org//files/sa-2006-011/4.7.2.patch].
>
> ------------REPORTED BY------------
>
> Ayman Hourieh
>
> ------------NOTE ABOUT DRUPAL 4.7.3 AND CUSTOM THEMES OR
> JAVASCRIPT------------
>
> A bug in the form API theme layer made it possible to have an ID occur
> more
> than once in a page. This invalidates the HTML, makes styling with CSS
> hard or
> impossible, and can break JavaScript. A patch was committed to ensure
> unique
> IDs. This patch has a side-effect that IDs for hidden form fields in your
> site's HTML will change. You might need to adapt your custom CSS or
> JavaScript, if it refers to such a changed ID.
>
> ------------CONTACT------------
>
> The security contact for Drupal can be reached at security at
> drupal.org or
> using the form at [http://drupal.org/contact].
>
>
>
> --
> Unsubscribe from this newsletter:
> http://drupal.org/newsletter/confirm/remove/508014ad8a206t44
>
> ------------------------------------------------------------------------
>
> _______________________________________________
> Imc-drupal-dev mailing list
> Imc-drupal-dev at lists.indymedia.org
> http://lists.indymedia.org/mailman/listinfo/imc-drupal-dev
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.indymedia.org/pipermail/imc-drupal-dev/attachments/20060803/6f375226/attachment.htm
More information about the Imc-drupal-dev
mailing list