SECURITY BLOG
SECURITY DASHBOARD
PARTNERS
PRODUCTS
JOBS
SERVICES
COMPANY
HOME
Security Dashboard
|
US-CERTs
|
SecurityFocus
|
Advisories
|
Exploits
|
Threats
|
Vulnerabilities
|
Risks
Network Security Consulting Advisories Article
Drupal Drupal Commons Module Access Security Bypass Vulnerability
http://www.securityfocus.com/bid/54393
Security Info
Bugtraq ID:
54393
Class:
Access Validation Error
CVE:
Remote:
Yes
Local:
No
Published:
Jul 11 2012 12:00AM
Updated:
Jul 11 2012 12:00AM
Credit:
Trevor English and Ezra Gildesgame
Vulnerable:
Not Vulnerable:
Security Discussion
The Drupal Commons module for Drupal is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized access; this may aid in launching further attacks.
Drupal Commons 6.x-2.x through versions prior to 6.x-2.8 are vulnerable.
Proof of Concept and Security Exploits
Attackers can exploit this issue through a browser.
Security Solution(s)
Solution:
Vendor updates are available. Please see the references for more information.
Security References(s)
References:
Drupal Homepage
(Drupal)
Site Updated May 20, 2013
©2000-2013 Emagined Security
All Rights Reserved
Secure Web Programming
by
Vizual Services