Drupal Live CSS Module Arbitrary PHP Code Execution Vulnerability
BID:57436
Info
Drupal Live CSS Module Arbitrary PHP Code Execution Vulnerability
| Bugtraq ID: | 57436 |
| Class: | Access Validation Error |
| CVE: |
CVE-2013-0206 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2013 12:00AM |
| Updated: | Jan 21 2013 12:50PM |
| Credit: | Ryan Garrett |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Drupal Live CSS Module Arbitrary PHP Code Execution Vulnerability
The Live CSS module for Drupal is prone to an arbitrary PHP code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary PHP code within the context of the web server.
The following versions are vulnerable:
Live CSS 6.x-2.x versions prior to 6.x-2.1
Live CSS 7.x-2.x versions prior to 7.x-2.7
The Live CSS module for Drupal is prone to an arbitrary PHP code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary PHP code within the context of the web server.
The following versions are vulnerable:
Live CSS 6.x-2.x versions prior to 6.x-2.1
Live CSS 7.x-2.x versions prior to 7.x-2.7
Exploit / POC
Drupal Live CSS Module Arbitrary PHP Code Execution Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
References
Drupal Live CSS Module Arbitrary PHP Code Execution Vulnerability
References:
References:
- Drupal Homepage (Drupal)