Vulnerability Bulletins |
SA-CORE-2012-003 - Drupal core - Arbitrary PHP code execution and Information disclosure |
|
| Affected software | Drupal |
|
Advisory ID: DRUPAL-SA-CORE-2012-003Project: Drupal coreVersion: 7.xDate: 2012-October-17Security risk: Highly criticalExploitable from: RemoteVulnerability: Information Disclosure, Arbitrary PHP code executionDescriptionMultiple vulnerabilities were discovered in Drupal core.Arbitrary PHP code executionA bug in the installer code was identified that allows an attacker to re-install Drupal using an external database server under certain transient conditions. This could allow the attacker to More info: https://www.drupal.org/SA-CORE-2012-003 |
|






