6

CVE-2012-2073

The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the "use PHP for settings" permission while importing settings, which allows remote authenticated users with certain permissions to execute arbitrary PHP code via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kristof De JaegerBundle Copy Version7.x-1.0
   DrupalDrupal Version-
Kristof De JaegerBundle Copy Version7.x-1.x
   DrupalDrupal Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.82% 0.759
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.openwall.com/lists/oss-security/2012/04/07/1
http://drupal.org/node/1506166
Patch
http://drupal.org/node/1506420
Patch
Vendor Advisory
http://drupalcode.org/project/bundle_copy.git/commit/299bdca
http://osvdb.org/80676
http://secunia.com/advisories/48626
Vendor Advisory
http://www.securityfocus.com/bid/52811
https://exchange.xforce.ibmcloud.com/vulnerabilities/74439