Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
|
Information
Published : 2016-04-12 08:59
Updated : 2016-05-09 10:46
NVD link : CVE-2016-3171
Mitre link : CVE-2016-3171
JSON object : View
CWE
CWE-19
Data Processing Errors
Products Affected
debian
- debian_linux
drupal
- drupal
php
- php