Drupal FileField Sources Module Arbitrary Code Execution Vulnerability
BID:42390
Info
Drupal FileField Sources Module Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 42390 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2010 12:00AM |
| Updated: | Aug 11 2010 12:00AM |
| Credit: | Apa Sajja |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Drupal FileField Sources Module Arbitrary Code Execution Vulnerability
The Drupal FileField Sources module is prone to an arbitrary code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the webserver process. This may facilitate a compromise of the application and the underlying computer; other attacks are also possible.
To exploit this issue, attackers require sufficient permission to create or edit a node that has FileField or FileField Sources configured on it.
Versions prior to FileField Sources 6.x-1.2 are vulnerable.
The Drupal FileField Sources module is prone to an arbitrary code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the webserver process. This may facilitate a compromise of the application and the underlying computer; other attacks are also possible.
To exploit this issue, attackers require sufficient permission to create or edit a node that has FileField or FileField Sources configured on it.
Versions prior to FileField Sources 6.x-1.2 are vulnerable.
Exploit / POC
Drupal FileField Sources Module Arbitrary Code Execution Vulnerability
Attackers can exploit this issue with a web browser.
Attackers can exploit this issue with a web browser.
Solution / Fix
Drupal FileField Sources Module Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Drupal FileField Sources Module Arbitrary Code Execution Vulnerability
References:
References: