Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

January 17th, 2013, 09:07 GMT · By

BLOG

Drupal 7.19 and 6.28 Released to Address XSS, Access Bypass Flaws

SHARE:

Adjust text size:


Drupal security update released Enlarge picture - Drupal security update released
On Wednesday, Drupal 7.19 and Drupal 6.28 were released. The security updates have been made available to address a cross-site scripting (XSS) and a couple of access bypass vulnerabilities that affect Drupal core 6.x and 7.x versions.

The reflected XSS vulnerability, which impacts both Drupal 6 and 7, affects certain JavaScript functions that “pass unexpected user input into jQuery causing it to insert HTML into the page when the intended behavior is to select DOM elements.”

The first access bypass vulnerability, affecting Drupal 6 and 7, exposes the title and, in some cases, the content of nodes which users should not be allowed to access.

The second access bypass flaw, which affects the “image” module in Drupal 7, allows an attacker to view the image derivatives of images that are marked as private files.

Users are advised to apply the updates as soon as possible.

Drupal is available for download here

TELL US WHAT YOU THINK:

1,250 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Adobe Patches Four Critical Vulnerabilities in ColdFusion

Java 7 Update 11 Addresses the Flaw Partly Fixed in October 2012, Experts Say

Oracle to Address 86 Vulnerabilities with January 2013 CPU

Update Google Chrome to Stay Safe, but Beware of Fakes

Google Fixes 24 Vulnerabilities with the Release of Chrome 24

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM