OSVDB ID: 70407

Title: Panels Module for Drupal CSS Properties Multiple Field XSS

Info

Disclosure

Jan 13, 2011

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Jan 12, 2011

Description

Panels Module for Drupal contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Upgrade
Exploit: Exploit Unknown
Disclosure: Vendor Verified
OSVDB: Web Related

Solution

Upgrade to version 6.x-3.9 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Earl Miles

Panels Module for Drupal

6.x-3.x-dev
6.x-3.0-alpha.x
6.x-3.0-beta.x
6.x-3.0-rc1
6.x-3.0
6.x-3.1
6.x-3.2
6.x-3.3
6.x-3.4
6.x-3.5
6.x-3.6
6.x-3.7
6.x-3.8

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/70407