CVE-2012-2073

The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the "use PHP for settings" permission while importing settings, which allows remote authenticated users with certain permissions to execute arbitrary PHP code via unspecified vectors.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:kristof_de_jaeger:bundle_copy:7.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:kristof_de_jaeger:bundle_copy:7.x-1.x:*:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:38

Type Values Removed Values Added
References () http://drupal.org/node/1506166 - Patch () http://drupal.org/node/1506166 - Patch
References () http://drupal.org/node/1506420 - Patch, Vendor Advisory () http://drupal.org/node/1506420 - Patch, Vendor Advisory
References () http://drupalcode.org/project/bundle_copy.git/commit/299bdca - () http://drupalcode.org/project/bundle_copy.git/commit/299bdca -
References () http://osvdb.org/80676 - () http://osvdb.org/80676 -
References () http://secunia.com/advisories/48626 - Vendor Advisory () http://secunia.com/advisories/48626 - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2012/04/07/1 - () http://www.openwall.com/lists/oss-security/2012/04/07/1 -
References () http://www.securityfocus.com/bid/52811 - () http://www.securityfocus.com/bid/52811 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/74439 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/74439 -

Information

Published : 2012-08-14 23:55

Updated : 2024-11-21 01:38


NVD link : CVE-2012-2073

Mitre link : CVE-2012-2073

CVE.ORG link : CVE-2012-2073


JSON object : View

Products Affected

drupal

  • drupal

kristof_de_jaeger

  • bundle_copy
CWE
CWE-264

Permissions, Privileges, and Access Controls