|
Family: CGI abuses --> Category: attack
Drupal XML-RPC for PHP Remote Code Injection Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks for XML-RPC for PHP remote code injection vulnerability in Drupal
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP application that is prone to
arbitrary PHP code injection attacks.
Description :
The version of Drupal installed on the remote host allows attackers to
execute arbitrary PHP code due to a flaw in its bundled XML-RPC
library.
See also :
http://www.gulftech.org/?node=research&article_id=00088-07022005
http://drupal.org/drupal-4.6.2
Solution :
Upgrade to Drupal version 4.5.4 / 4.6.2 or later or remove the
'xmlrpc.php' script.
Threat Level:
High / CVSS Base Score : 7
(AV:R/AC:L/Au:NR/C:P/A:P/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|