Drupal Simplenews Scheduler Module Arbitrary PHP Code Execution Vulnerability
BID:55616
Info
Drupal Simplenews Scheduler Module Arbitrary PHP Code Execution Vulnerability
| Bugtraq ID: | 55616 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 19 2012 12:00AM |
| Updated: | Sep 19 2012 12:00AM |
| Credit: | Sascha Grossenbacher and Joachim Noreiko |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Drupal Simplenews Scheduler Module Arbitrary PHP Code Execution Vulnerability
The Drupal Simplenews Scheduler module is prone to an arbitrary PHP code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary PHP code within the context of the web server.
Simplenews Scheduler 6.x-2.x versions prior to 6.x-2.3 are vulnerable.
The Drupal Simplenews Scheduler module is prone to an arbitrary PHP code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary PHP code within the context of the web server.
Simplenews Scheduler 6.x-2.x versions prior to 6.x-2.3 are vulnerable.
Exploit / POC
Drupal Simplenews Scheduler Module Arbitrary PHP Code Execution Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Drupal Simplenews Scheduler Module Arbitrary PHP Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Drupal Simplenews Scheduler Module Arbitrary PHP Code Execution Vulnerability
References:
References: