[Security-news] SA-CONTRIB-2010-070 - Multiple vulnerabilities in multiple contributed modules

security-news at drupal.org security-news at drupal.org
Wed Jun 23 20:53:43 UTC 2010


  * Advisory ID: DRUPAL-SA-CONTRIB-2010-070
  * Projects: Multiple third party modules - Easy Translator, Block Queue,
    Multiple Image Upload (Imagex)
  * Version: 5.x, 6.x
  * Date: 2010-06-23
  * Security risks: Critical
  * Exploitable from: Remote
  * Vulnerability: Multiple (SQL Injection, CSRF, Access bypass)

-------- VERSIONS AFFECTED AND PROPOSED SOLUTIONS  
----------------------------

Easy Translator [1] for Drupal 6.x
     The module is vulnerable to SQL injections. *Solution:* Disable the
     module. There is no safe version of the module to use.

Block Queue [2] for Drupal 6.x
     The Block Queue module allows users to create "queues" of blocks much
     like NodeQueue allows to create queues for nodes. The module is
     vulnerable to Cross-Site Request Forgeries as it allows a non-admin user
     to trick an admin into removing blocks from queues by directing him/her
     to a url via a link or image. *Solution:* Disable the module. There is no
     safe version of the module to use.

Multiple Image Upload (Imagex) [3] for Drupal 5.x and 6.x
     The Multiple Image Upload module enables images to be "drag 'n' dropped"
     uploaded into Drupal. The module is vulnerable to access bypass.
     *Solution:* Disable the module. There is no safe version of the module to
     use. All releases of the module were marked unsupported earlier.

Drupal core is not affected. If you do not use any of the module releases
above there is nothing you need to do.
-------- ONGOING MAINTENANCE OF THESE MODULES  
--------------------------------

If you are interested in taking over maintenance of a module, or branch of a
module, that is no longer supported, and are capable of fixing security
vulnerabilities, you may apply to do so using the abandoned project takeover
process [4].
-------- REPORTED BY  
---------------------------------------------------------

  * Easy Translator issue reported by Jakub Suchy [5] of the Drupal Security
    Team
  * Blockqueue issue reported by mr.baileys [6] of the Drupal Security Team
  * Multiple Image Upload (Imagex) issue reported by Greg Knaddison [7] of the
    Drupal Security Team
-------- CONTACT  
-------------------------------------------------------------

The security team for Drupal [8] can be reached at security at drupal.org or
via the form at http://drupal.org/contact.
Read more about the Security Team and Security Advisories at
http://drupal.org/security.




[1] http://drupal.org/project/vitzo_easy_translator
[2] http://drupal.org/project/blockqueue
[3] http://drupal.org/project/imagex
[4] http://drupal.org/node/251466
[5] http://drupal.org/user/31977
[6] http://drupal.org/user/383424
[7] http://drupal.org/user/36762
[8] http://drupal.org/security-team



More information about the Security-news mailing list