Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Drupal Talk Module Multiple Remote Vulnerabilities

The Talk module for Drupal is prone to multiple remote vulnerabilities:

1. An HTML-injection vulnerability allows attackers to potentially steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.

2. An access-validation vulnerability allows attackers to view arbitrary nodes.

These issues affect versions prior to Talk 5.x-1.3 and Talk 6.x-1.5.
http://drupal.org/node/207891







 

Privacy Statement
Copyright 2009, SecurityFocus