Contact Us
SECURITY BLOG SECURITY DASHBOARD PARTNERS PRODUCTS JOBS SERVICES COMPANY HOME
Network Security Consulting Advisories Article

Drupal Drupal Commons Module Access Security Bypass Vulnerability

http://www.securityfocus.com/bid/54393

Security Info

Bugtraq ID: 54393
Class: Access Validation Error
CVE:
Remote: Yes
Local: No
Published: Jul 11 2012 12:00AM
Updated: Jul 11 2012 12:00AM
Credit: Trevor English and Ezra Gildesgame
Vulnerable:
Not Vulnerable:

Security Discussion

The Drupal Commons module for Drupal is prone to a security-bypass vulnerability.

An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized access; this may aid in launching further attacks.

Drupal Commons 6.x-2.x through versions prior to 6.x-2.8 are vulnerable.

Proof of Concept and Security Exploits

Attackers can exploit this issue through a browser.

Security Solution(s)

Solution:
Vendor updates are available. Please see the references for more information.

Security References(s)

References:

Contact Us

Security Penetration Testing

Security Questions

Security Dashboard

Emagined Security Blog featuring Dr. Eugene Schultz
Site Updated May 20, 2013
©2000-2013 Emagined Security
All Rights Reserved

Secure Web Programming
by Vizual Services