SB2012111101 - Arbitrary PHP code execution in Drupal Drupal



SB2012111101 - Arbitrary PHP code execution in Drupal Drupal

Published: November 11, 2012 Updated: March 14, 2017

Security Bulletin ID SB2012111101
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Arbitrary PHP code execution (CVE-ID: CVE-2012-4553)

The vulnerability allows a remote user to cause arbitrary code execution on the original server.
The weakness is caused by identification of bug in the installer code. By using external database attacker can reinstall Drupal and cause arbitrary PHP code execution.
Successful exploitation of the vulnerability allows a malicious user to trigger arbitary code execution on the vunerable server.

Remediation

Install update from vendor's website.