First published: Wed Jun 18 2008(Updated: )
The Magic Tabs module 5.x before 5.x-1.1 for Drupal allows remote attackers to execute arbitrary PHP code via unspecified URL arguments, possibly related to a missing "whitelist of callbacks."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Quick Tabs | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2772 has a severity rating that indicates a high risk of remote code execution.
To fix CVE-2008-2772, update the Magic Tabs module to version 5.x-1.1 or later.
CVE-2008-2772 affects the Magic Tabs module version 5.x for the Drupal content management system.
CVE-2008-2772 allows remote attackers to execute arbitrary PHP code through improper handling of URL arguments.
Yes, there are reports of public exploits that target the vulnerability in CVE-2008-2772.