CVE-2012-1641

The finder_import function in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote authenticated users with the administer finder permission to execute arbitrary PHP code via admin/build/finder/import.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:danielb:finder:6.x-1.16:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.15:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.14:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.13:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:rc4:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:rc3:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:rc2:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha19:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha18:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha17:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha22:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha16:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:7.x-1.6:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.2:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:unstable7:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:7.x-1.4:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.4:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:7.x-2.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.11:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.18:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.9:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha13:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:unstable6:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:beta3:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:beta1:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.20:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:7.x-1.5:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:7.x-2.x:dev:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha15:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha20:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha9:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:unstable1:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha10:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.24:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.12:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha12:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha8:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.3:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.8:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:unstable2:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha21:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha24:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha27:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.17:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:beta2:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:unstable0:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha14:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.21:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.5:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:7.x-1.x:dev:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:7.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha26:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:7.x-2.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.19:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.6:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:7.x-1.2:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.10:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha23:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha28:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha11:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:7.x-2.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:7.x-2.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.23:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:unstable5:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha25:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.x-dev:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.1:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:alpha7:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.7:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:unstable4:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:7.x-1.1:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:7.x-1.3:*:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:7.x-2.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:6.x-1.0:unstable3:*:*:*:*:*:*
cpe:2.3:a:danielb:finder:7.x-2.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*

Information

Published : 2012-08-28 10:55

Updated : 2012-08-28 21:00


NVD link : CVE-2012-1641

Mitre link : CVE-2012-1641


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

drupal

  • drupal

danielb

  • finder