* Advisory ID: DRUPAL-SA-CONTRIB-2010-070 * Projects: Multiple third party modules - Easy Translator, Block Queue, Multiple Image Upload (Imagex) * Version: 5.x, 6.x * Date: 2010-06-23 * Security risks: Critical * Exploitable from: Remote * Vulnerability: Multiple (SQL Injection, CSRF, Access bypass)
-------- VERSIONS AFFECTED AND PROPOSED SOLUTIONS ----------------------------
Easy Translator [1] for Drupal 6.x The module is vulnerable to SQL injections. *Solution:* Disable the module. There is no safe version of the module to use.
Block Queue [2] for Drupal 6.x The Block Queue module allows users to create "queues" of blocks much like NodeQueue allows to create queues for nodes. The module is vulnerable to Cross-Site Request Forgeries as it allows a non-admin user to trick an admin into removing blocks from queues by directing him/her to a url via a link or image. *Solution:* Disable the module. There is no safe version of the module to use.
Multiple Image Upload (Imagex) [3] for Drupal 5.x and 6.x The Multiple Image Upload module enables images to be "drag 'n' dropped" uploaded into Drupal. The module is vulnerable to access bypass. *Solution:* Disable the module. There is no safe version of the module to use. All releases of the module were marked unsupported earlier.
Drupal core is not affected. If you do not use any of the module releases above there is nothing you need to do. -------- ONGOING MAINTENANCE OF THESE MODULES --------------------------------
If you are interested in taking over maintenance of a module, or branch of a module, that is no longer supported, and are capable of fixing security vulnerabilities, you may apply to do so using the abandoned project takeover process [4]. -------- REPORTED BY ---------------------------------------------------------
* Easy Translator issue reported by Jakub Suchy [5] of the Drupal Security Team * Blockqueue issue reported by mr.baileys [6] of the Drupal Security Team * Multiple Image Upload (Imagex) issue reported by Greg Knaddison [7] of the Drupal Security Team -------- CONTACT -------------------------------------------------------------
The security team for Drupal [8] can be reached at security at drupal.org or via the form at http://drupal.org/contact. Read more about the Security Team and Security Advisories at http://drupal.org/security.
[1] http://drupal.org/project/vitzo_easy_translator [2] http://drupal.org/project/blockqueue [3] http://drupal.org/project/imagex [4] http://drupal.org/node/251466 [5] http://drupal.org/user/31977 [6] http://drupal.org/user/383424 [7] http://drupal.org/user/36762 [8] http://drupal.org/security-team