Panels Module For Drupal Arbitrary PHP Code Execution Vulnerability
BID:40286
Info
Panels Module For Drupal Arbitrary PHP Code Execution Vulnerability
| Bugtraq ID: | 40286 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2010 12:00AM |
| Updated: | May 20 2010 12:00AM |
| Credit: | Sam Boyer |
| Vulnerable: |
Panels Panels 6.x-3.x-dev |
| Not Vulnerable: |
Panels Panels 6.x-3.4 |
Discussion
Panels Module For Drupal Arbitrary PHP Code Execution Vulnerability
The Panels module for Drupal is prone to a vulnerability that lets attackers execute arbitrary PHP code because it fails to sufficiently restrict user access.
An attacker can exploit this issues to execute arbitrary PHP code within the context of the webserver.
Versions of Panels prior to 6.x-3.4 are vulnerable.
The Panels module for Drupal is prone to a vulnerability that lets attackers execute arbitrary PHP code because it fails to sufficiently restrict user access.
An attacker can exploit this issues to execute arbitrary PHP code within the context of the webserver.
Versions of Panels prior to 6.x-3.4 are vulnerable.
Exploit / POC
Panels Module For Drupal Arbitrary PHP Code Execution Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Panels Module For Drupal Arbitrary PHP Code Execution Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Panels Module For Drupal Arbitrary PHP Code Execution Vulnerability
References:
References:
- Drupal Language Switcher Dropdown Homepage (Drupal)
- Panels - Homepage (Panels)
- SA-CONTRIB-2010-059: Panels - Arbitrary PHP code execution (Sam Boyer)