Drupal Embedded Media Field Module Multiple XSS

2009.05.30
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Details of this disclosure are posted at http://lampsecurity.org/drupal-6-embed-media-xss-vulnerability Vendor notified: 5/27/09 Vendor response: (see below) Description of Vulnerability: - ----------------------------- Drupal (http://drupal.org) is a robust content management system (CMS) written in PHP and MySQL that provides extensibility through various third party modules. The Embedded Media Field (http://drupal.org/project/emfield) module is a Content Construction Kit (CCK) module that allows for the creation of node content types that can be used for displaying video, image or audio files from a third party. The Embedded Media Field module contains several cross site scripting (XSS) vulnerabilities: The Embedded Media Field module contains a XSS vulnerability because it does not properly sanitize the output of 'Help text', 'Custom thumbnail label', of 'Custom thumbnail description' specified when creating an Embedded Media Field content type field. Systems affected: - ----------------- Drupal 6.12 with CCK 6.x-2.2 and Embedded Media Field 6.x-1.0 was tested and shown to be vulnerable. Impact: - ------- XSS vulnerabilities may expose site administrative accounts to compromise which could lead to web server process compromise. Mitigating factors: - ------------------- The Embedded Media Field module must be installed. Only users who have rights to create content or administer content types are exposed to the XSS, although these accounts are generally privileged, representing a greater risk. 'Administer content types' privilege is required to carry out the proof of concept below, although other vectors may exist. Vendor Response: - ---------------- Vendor has filed a bug report with module maintainer at http://drupal.org/node/474790. Proof of concept: - ----------------- 1. Install Drupal 6.12 and CCK. 2. Install Embedded Media Field and enable all Print functionality through Administer-> Modules. 3. Adjust fields in the 'Story' content type by clicking on Administer - -> Content management -> Content types, then clicking 'manage fields' next to 'Story' 4. In the 'Add' field type in an arbitrary field label and field name in the 'New field' area 5. Select 'Embedded Video' from the 'Type of data to store' drop down 6. Click the 'Save' button 7. On the resultant screen fill in "<script>alert('custom thumbnail label xss');</script>" in the "Custom thumbnail label:" text field 8. Fill in "<script>alert('custom thumbnail description xss');</script>" in the "Custom thumbnail description:" text field 9. Fill in " 10. Click the 'Save field settings' button 11. Create new content of the type by clicking the 'Create content' link then the 'Story' link 12. Observe multiple JavaScript alerts - -- Justin C. Klein Keane http://www.MadIrish.net http://www.LAMPSecurity.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iQD1AwUBSh6YjZEpbGy7DdYAAQJNsgb/T3zxhzwE5Y3wiG5bZ/64i7S9fn/TpV2V fukx2r3ttPex3fLl+SYNFfU8wVV78l33q3TZKn9iudp1dw4ENav94WcOff9zrwKQ mJS6BVUUco+dVIO+AaX6YCe7a0DX2vcXT7tJY+/AlcL3DtVywJUXAvwdMRrtbCXC uAiLHaIrRc+J3BxxwMkMIPMn4Do1NJGJHpSCQUpmhj4nMZBA9LWqJLDUdo1sqp6V eEBIWxd31pO8Nm6UODAunBmGtfGziijv3BoZ0xxtTx2k4n1tO3Ierg/EjnHkNmdK Zmb7PEickN0= =pMOG -----END PGP SIGNATURE-----

References:

http://seclists.org/fulldisclosure/2009/May/0257.html


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top