Vulnerability Bulletins |
SA-CORE-2012-003 - Drupal core - Arbitrary PHP code execution and Information disclosure |
|
| Affected software | Drupal |
|
Advisory ID: DRUPAL-SA-CORE-2012-003Project: Drupal coreVersion: 7.xDate: 2012-October-17Security risk: Highly criticalExploitable from: RemoteVulnerability: Information Disclosure, Arbitrary PHP code executionDescriptionMultiple vulnerabilities were discovered in Drupal core.Arbitrary PHP code executionA bug in the installer code was identified that allows an attacker to re-install Drupal using an external database server under certain transient conditions. This could allow the attacker to More info: https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2012-10-17/sa-core-2012-003-drupal-core |
|






