Drupal Drag & Drop Gallery Module Arbitrary PHP Code Execution Vulnerability
BID:54380
Info
Drupal Drag & Drop Gallery Module Arbitrary PHP Code Execution Vulnerability
| Bugtraq ID: | 54380 |
| Class: | Access Validation Error |
| CVE: |
CVE-2012-4472 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2012 12:00AM |
| Updated: | Oct 04 2012 02:10PM |
| Credit: | Unknown |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Drupal Drag & Drop Gallery Module Arbitrary PHP Code Execution Vulnerability
The Drupal Drag & Drop Gallery module is prone to an arbitrary PHP code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary PHP code within the context of the web server.
Drag & Drop Gallery 6.x are vulnerable.
The Drupal Drag & Drop Gallery module is prone to an arbitrary PHP code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary PHP code within the context of the web server.
Drag & Drop Gallery 6.x are vulnerable.
Exploit / POC
Drupal Drag & Drop Gallery Module Arbitrary PHP Code Execution Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Drupal Drag & Drop Gallery Module Arbitrary PHP Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Drupal Drag & Drop Gallery Module Arbitrary PHP Code Execution Vulnerability
References:
References:
- Drupal Homepage (Drupal)