6.8

CVE-2013-4446

The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP that does not support the json_decode function, allows remote attackers to execute arbitrary PHP code via unspecified vectors related to Ajax operations, possibly involving eval injection.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Steven Jones ≫ Context Version 6.x-2.0 Update alpha1
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-2.0 Update alpha2
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-2.0 Update beta1
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-2.0 Update beta2
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-2.0 Update beta3
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-2.0 Update beta4
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-2.0 Update beta5
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-2.0 Update beta6
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-2.0 Update beta7
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-2.0 Update rc1
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-2.0 Update rc2
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-2.0 Update rc3
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-3.0
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-3.0 Update alpha1
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-3.0 Update alpha2
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-3.0 Update beta1
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-3.0 Update beta2
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-3.0 Update beta3
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-3.0 Update beta4
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-3.0 Update beta5
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-3.0 Update beta6
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-3.0 Update beta7
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-3.0 Update beta8
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-3.0 Update rc1
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-3.0 Update rc2
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-3.1
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 6.x-3.x Update dev
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 7.x-3.0 Update alpha1
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 7.x-3.0 Update alpha2
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 7.x-3.0 Update alpha3
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 7.x-3.0 Update beta1
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 7.x-3.0 Update beta2
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 7.x-3.0 Update beta3
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 7.x-3.0 Update beta4
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 7.x-3.0 Update beta5
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 7.x-3.0 Update beta6
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 7.x-3.0 Update beta7
   Drupal ≫ Drupal Version -
Steven Jones ≫ Context Version 7.x-3.x Update dev
   Drupal ≫ Drupal Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.53% 0.715
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://lists.fedoraproject.org/pipermail/package-announce/2013-November/121433.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122298.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122308.html
https://drupal.org/node/2112785
Patch
https://drupal.org/node/2112791
Patch
https://drupal.org/node/2113317
Patch
Vendor Advisory
http://drupalcode.org/project/context.git/commitdiff/63ef4d9
Patch
http://drupalcode.org/project/context.git/commitdiff/d7b4afa
Patch