SB2012111101 - Arbitrary PHP code execution in Drupal Drupal
Published: November 11, 2012 Updated: March 14, 2017
Security Bulletin ID
SB2012111101
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Arbitrary PHP code execution (CVE-ID: CVE-2012-4553)
The vulnerability allows a remote user to cause arbitrary code execution on the original server.The weakness is caused by identification of bug in the installer code. By using external database attacker can reinstall Drupal and cause arbitrary PHP code execution.
Successful exploitation of the vulnerability allows a malicious user to trigger arbitary code execution on the vunerable server.
Remediation
Install update from vendor's website.