|
|
| |
|
| |
drupal7: code execution
| Package(s): | drupal7 |
CVE #(s): | |
| Created: | October 29, 2012 |
Updated: | October 31, 2012 |
| Description: |
From the Drupal advisory:
A bug in the installer code was identified that allows an attacker to re-install Drupal using an external database server under certain transient conditions. This could allow the attacker to execute arbitrary PHP code on the original server. |
| Alerts: |
|
( Log in to post comments)
|
|
|