Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Drupal Audio And MediaField Modules GetID3 Remote Command Execution Vulnerability

Drupal is prone to a remote command-execution vulnerability because the application fails to properly sanitize user-supplied input.

Attackers can exploit this issue to execute arbitrary commands in the context of the webserver. A successful attack will allow an attacker to read and delete arbitrary files and to write arbitrary data to empty or MP3 files.







 

Privacy Statement
Copyright 2009, SecurityFocus