Drupal Ctools Module Cross Site Scripting and Access Bypass Vulnerabilities

The Ctools module for Drupal is prone to a cross-site scripting vulnerability and an access-bypass vulnerability.

An attacker can exploit these issues to execute arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials and to bypass security restrictions, or perform unauthorized actions; this may aid in launching further attacks.


 

Privacy Statement
Copyright 2010, SecurityFocus