Drupal PDFThumb Module Command Injection Vulnerability
BID:55528
Info
Drupal PDFThumb Module Command Injection Vulnerability
| Bugtraq ID: | 55528 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2012 12:00AM |
| Updated: | Sep 12 2012 12:00AM |
| Credit: | Matt Kleve and mdespeuilles |
| Vulnerable: |
Drupal PDFThumb 7.x-1.0 |
| Not Vulnerable: |
Drupal PDFThumb 7.x-1.1 |
Discussion
Drupal PDFThumb Module Command Injection Vulnerability
The PDFThumb module for Drupal is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary commands in the context of the web server process. Successful exploits could compromise the application and possibly the underlying system.
PDFThumb 7.x-1.x versions prior to 7.x-1.1 are vulnerable.
The PDFThumb module for Drupal is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary commands in the context of the web server process. Successful exploits could compromise the application and possibly the underlying system.
PDFThumb 7.x-1.x versions prior to 7.x-1.1 are vulnerable.
Exploit / POC
Drupal PDFThumb Module Command Injection Vulnerability
An attacker can exploit the issue through a browser.
An attacker can exploit the issue through a browser.
References
Drupal PDFThumb Module Command Injection Vulnerability
References:
References:
- PDFThumb Homepage (Drupal)
- SA-CONTRIB-2012-139 - PDFThumb OS Injection (Drupal)