Drupal Core Arbitrary PHP Code Execution and Information Disclosure Vulnerabilities
BID:56103
Info
Drupal Core Arbitrary PHP Code Execution and Information Disclosure Vulnerabilities
| Bugtraq ID: | 56103 |
| Class: | Access Validation Error |
| CVE: |
CVE-2012-4553 CVE-2012-4554 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2012 12:00AM |
| Updated: | Apr 16 2015 05:50PM |
| Credit: | Heine Deelstra and Reginaldo Silva. |
| Vulnerable: |
Drupal Drupal 7.14 Drupal Drupal 7.13 Drupal Drupal 7.12 Drupal Drupal 7.11 Drupal Drupal 7.10 |
| Not Vulnerable: | |
Discussion
Drupal Core Arbitrary PHP Code Execution and Information Disclosure Vulnerabilities
Drupal is prone to an arbitrary PHP code-execution and an information-disclosure vulnerability.
An attacker can exploit these issues to execute arbitrary PHP code within the context of the web server and obtain sensitive information that may aid in launching further attacks.
Versions prior to Drupal 7.16 are vulnerable.
Drupal is prone to an arbitrary PHP code-execution and an information-disclosure vulnerability.
An attacker can exploit these issues to execute arbitrary PHP code within the context of the web server and obtain sensitive information that may aid in launching further attacks.
Versions prior to Drupal 7.16 are vulnerable.
Exploit / POC
Drupal Core Arbitrary PHP Code Execution and Information Disclosure Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Drupal Core Arbitrary PHP Code Execution and Information Disclosure Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Drupal Core Arbitrary PHP Code Execution and Information Disclosure Vulnerabilities
References:
References:
- Drupal Homepage (Drupal)