6.8
CVE-2013-4446
- EPSS 1.53%
- Veröffentlicht 07.12.2013 20:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP that does not support the json_decode function, allows remote attackers to execute arbitrary PHP code via unspecified vectors related to Ajax operations, possibly involving eval injection.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Steven Jones ≫ Context Version 6.x-2.0 Update alpha1
Steven Jones ≫ Context Version 6.x-2.0 Update alpha2
Steven Jones ≫ Context Version 6.x-2.0 Update beta1
Steven Jones ≫ Context Version 6.x-2.0 Update beta2
Steven Jones ≫ Context Version 6.x-2.0 Update beta3
Steven Jones ≫ Context Version 6.x-2.0 Update beta4
Steven Jones ≫ Context Version 6.x-2.0 Update beta5
Steven Jones ≫ Context Version 6.x-2.0 Update beta6
Steven Jones ≫ Context Version 6.x-2.0 Update beta7
Steven Jones ≫ Context Version 6.x-2.0 Update rc1
Steven Jones ≫ Context Version 6.x-2.0 Update rc2
Steven Jones ≫ Context Version 6.x-2.0 Update rc3
Steven Jones ≫ Context Version 6.x-3.0
Steven Jones ≫ Context Version 6.x-3.0 Update alpha1
Steven Jones ≫ Context Version 6.x-3.0 Update alpha2
Steven Jones ≫ Context Version 6.x-3.0 Update beta1
Steven Jones ≫ Context Version 6.x-3.0 Update beta2
Steven Jones ≫ Context Version 6.x-3.0 Update beta3
Steven Jones ≫ Context Version 6.x-3.0 Update beta4
Steven Jones ≫ Context Version 6.x-3.0 Update beta5
Steven Jones ≫ Context Version 6.x-3.0 Update beta6
Steven Jones ≫ Context Version 6.x-3.0 Update beta7
Steven Jones ≫ Context Version 6.x-3.0 Update beta8
Steven Jones ≫ Context Version 6.x-3.0 Update rc1
Steven Jones ≫ Context Version 6.x-3.0 Update rc2
Steven Jones ≫ Context Version 6.x-3.1
Steven Jones ≫ Context Version 6.x-3.x Update dev
Steven Jones ≫ Context Version 7.x-3.0 Update alpha1
Steven Jones ≫ Context Version 7.x-3.0 Update alpha2
Steven Jones ≫ Context Version 7.x-3.0 Update alpha3
Steven Jones ≫ Context Version 7.x-3.0 Update beta1
Steven Jones ≫ Context Version 7.x-3.0 Update beta2
Steven Jones ≫ Context Version 7.x-3.0 Update beta3
Steven Jones ≫ Context Version 7.x-3.0 Update beta4
Steven Jones ≫ Context Version 7.x-3.0 Update beta5
Steven Jones ≫ Context Version 7.x-3.0 Update beta6
Steven Jones ≫ Context Version 7.x-3.0 Update beta7
Steven Jones ≫ Context Version 7.x-3.x Update dev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.53% | 0.715 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/121433.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122298.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122308.html
https://drupal.org/node/2112785
https://drupal.org/node/2112791
https://drupal.org/node/2113317
http://drupalcode.org/project/context.git/commitdiff/63ef4d9
http://drupalcode.org/project/context.git/commitdiff/d7b4afa