header-logo
Suggest Exploit
vendor:
Drupal
by:
dab@digitalsec.net
7,5
CVSS
HIGH
php injection in comments
94
CWE
Product Name: Drupal
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005

DRUPAL-SA-2005-002 php injection in comments

A vulnerability in Drupal allows an attacker to inject arbitrary PHP code into comments. This vulnerability is due to insufficient sanitization of user-supplied input in the comment module. By sending a specially crafted request, an attacker can exploit this vulnerability to inject arbitrary PHP code into comments, which will be executed in the context of the web server process.

Mitigation:

Upgrade to the latest version of Drupal or apply the patch from the vendor.
Source

Exploit-DB raw data: