Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-3453

Overview

Vulnerability Score 6.5 6.5
CVE Id CVE-2014-3453
Last Modified 19 May 2014 12:32:02
Published 17 May 2014 03:55:03
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2014-3453

Summary

Eval injection vulnerability in the flag_import_form_validate function in includes/flag.export.inc in the Flag module 7.x-3.0, 7.x-3.5, and earlier for Drupal allows remote authenticated administrators to execute arbitrary PHP code via the "Flag import code" text area to admin/structure/flags/import. NOTE: this issue could also be exploited by other attackers if the administrator ignores a security warning on the permissions assignment page.

Vulnerable Systems

Application

  • Flag Module Project Flag 7.x-3.0

  • Flag Module Project Flag 7.x-3.1

  • Flag Module Project Flag 7.x-3.2

  • Flag Module Project Flag 7.x-3.3

  • Flag Module Project Flag 7.x-3.4

  • Flag Module Project Flag 7.x-3.5

  • Flag Module Project Flag 7.x-3.x


References

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=1096604

BID - 67318

MLIST - [oss-security] 20140512 Re: CVE request: Drupal Flag 7.x-3.5 Module Vulnerability report: Arbitrary code execution due to improper input handling in flag importer

FULLDISC - 20140509 Drupal Flag 7.x-3.5 Module Vulnerability report: Arbitrary code execution due to improper input handling in flag importer


Last Updated: 27 May 2016 11:05:19