MEDIUM · 6.0

CVE-2012-2073

The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the "use PHP for settings" permission while importing settings, which allows remote authenticated users with certain permiss...

Vulnerability Description

The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the "use PHP for settings" permission while importing settings, which allows remote authenticated users with certain permissions to execute arbitrary PHP code via unspecified vectors.

CVSS Score

6.0

MEDIUM

AV:N/AC:M/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Kristof De JaegerBundle Copy7.x-1.0
DrupalDrupal-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-2073?

CVE-2012-2073 is a vulnerability with a CVSS score of 6.0 (MEDIUM). The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the "use PHP for settings" permission while importing settings, which allows remote authenticated users with certain permiss...

How severe is CVE-2012-2073?

CVE-2012-2073 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-2073?

Check the references section above for vendor advisories and patch information. Affected products include: Kristof De Jaeger Bundle Copy, Drupal Drupal.