vendor:
Drupal
by:
Devin Zuczek, Mehmet Ince
N/A
CVSS
HIGH
Arbitrary PHP Execution
94
CWE
Product Name: Drupal
Affected Version From: Unknown
Affected Version To: 7.x
Patch Exists: YES
Related CWE:
CPE: a:drupal:drupal
Platforms Tested:
2016
Drupal RESTWS Module 7.x Remote PHP Code Execution
This module exploits the Drupal RESTWS module vulnerability. RESTWS alters the default page callbacks for entities to provide additional functionality. A vulnerability in this approach allows an unauthenticated attacker to send specially crafted requests resulting in arbitrary PHP execution. This module was tested against RESTWS 7.x with Drupal 7.5 installation on Ubuntu server.
Mitigation:
Update to the latest version of Drupal and RESTWS module.