{"api_version":"1","generated_at":"2026-07-23T13:34:53+00:00","cve":"CVE-2012-2073","urls":{"html":"https://cve.report/CVE-2012-2073","api":"https://cve.report/api/cve/CVE-2012-2073.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-2073","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-2073"},"summary":{"title":"CVE-2012-2073","description":"The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the \"use PHP for settings\" permission while importing settings, which allows remote authenticated users with certain permissions to execute arbitrary PHP code via unspecified vectors.","state":"PUBLISHED","assigner":"redhat","published_at":"2012-08-14 23:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6","severity":"","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","baseScore":6,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2012/04/07/1","name":"http://www.openwall.com/lists/oss-security/2012/04/07/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - CVE's for Drupal Contrib 2012 001 through 057 (67 new CVE assignments)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/1506166","name":"http://drupal.org/node/1506166","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"bundle_copy 7.x-1.1 | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/52811","name":"http://www.securityfocus.com/bid/52811","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Drupal Bundle Copy Module Arbitrary PHP Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://osvdb.org/80676","name":"http://osvdb.org/80676","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://drupalcode.org/project/bundle_copy.git/commit/299bdca","name":"http://drupalcode.org/project/bundle_copy.git/commit/299bdca","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"drupalcode.org Git - project/bundle_copy.git/commit","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/1506420","name":"http://drupal.org/node/1506420","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SA-CONTRIB-2012-046 - Bundle Copy - Arbitrary Code execution | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/48626","name":"http://secunia.com/advisories/48626","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA48626 - Drupal Bundle copy Module &quot;use PHP for settings&quot; Security Bypass Vulnerability - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/74439","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/74439","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-2073","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-2073","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"2073","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"drupal","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"2073","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kristof_de_jaeger","cpe5":"bundle_copy","cpe6":"7.x-1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"2073","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kristof_de_jaeger","cpe5":"bundle_copy","cpe6":"7.x-1.x","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T19:17:27.836Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://drupal.org/node/1506420"},{"name":"80676","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/80676"},{"name":"bundlecopy-usephp-code-execution(74439)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/74439"},{"name":"48626","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/48626"},{"name":"[oss-security] 20120406 CVE's for Drupal Contrib 2012 001 through 057 (67 new CVE assignments)","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/04/07/1"},{"name":"52811","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/52811"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/1506166"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupalcode.org/project/bundle_copy.git/commit/299bdca"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-03-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the \"use PHP for settings\" permission while importing settings, which allows remote authenticated users with certain permissions to execute arbitrary PHP code via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_MISC"],"url":"http://drupal.org/node/1506420"},{"name":"80676","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/80676"},{"name":"bundlecopy-usephp-code-execution(74439)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/74439"},{"name":"48626","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/48626"},{"name":"[oss-security] 20120406 CVE's for Drupal Contrib 2012 001 through 057 (67 new CVE assignments)","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/04/07/1"},{"name":"52811","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/52811"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/1506166"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupalcode.org/project/bundle_copy.git/commit/299bdca"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2012-2073","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the \"use PHP for settings\" permission while importing settings, which allows remote authenticated users with certain permissions to execute arbitrary PHP code via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://drupal.org/node/1506420","refsource":"MISC","url":"http://drupal.org/node/1506420"},{"name":"80676","refsource":"OSVDB","url":"http://osvdb.org/80676"},{"name":"bundlecopy-usephp-code-execution(74439)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/74439"},{"name":"48626","refsource":"SECUNIA","url":"http://secunia.com/advisories/48626"},{"name":"[oss-security] 20120406 CVE's for Drupal Contrib 2012 001 through 057 (67 new CVE assignments)","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2012/04/07/1"},{"name":"52811","refsource":"BID","url":"http://www.securityfocus.com/bid/52811"},{"name":"http://drupal.org/node/1506166","refsource":"CONFIRM","url":"http://drupal.org/node/1506166"},{"name":"http://drupalcode.org/project/bundle_copy.git/commit/299bdca","refsource":"CONFIRM","url":"http://drupalcode.org/project/bundle_copy.git/commit/299bdca"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2012-2073","datePublished":"2012-08-14T23:00:00.000Z","dateReserved":"2012-04-04T00:00:00.000Z","dateUpdated":"2024-08-06T19:17:27.836Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-08-14 23:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","baseScore":6,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:kristof_de_jaeger:bundle_copy:7.x-1.0:*:*:*:*:*:*:*","matchCriteriaId":"440C7474-3DA7-4DED-8D48-02B92BB456B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:kristof_de_jaeger:bundle_copy:7.x-1.x:*:*:*:*:*:*:*","matchCriteriaId":"1272D313-8A8C-4599-9620-CA0D5371BA88"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*","matchCriteriaId":"F8B1170D-AD33-4C7A-892D-63AC71B032CF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"2073","Ordinal":"1","Title":"CVE-2012-2073","CVE":"CVE-2012-2073","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"2073","Ordinal":"1","NoteData":"The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the \"use PHP for settings\" permission while importing settings, which allows remote authenticated users with certain permissions to execute arbitrary PHP code via unspecified vectors.","Type":"Description","Title":"CVE-2012-2073"},{"CveYear":"2012","CveId":"2073","Ordinal":"2","NoteData":"2012-08-14","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"2073","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}