CVE-2010-1546: Code Injection
Multiple eval injection vulnerabilities in the import functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with "administer page manager" privileges, to execute arbitrary PHP code via input to a text area, related to (1) the pagemanagerpageimportsubtaskvalidate function in pagemanager/plugins/tasks/page.admin.inc and (2) the pagemanagerhandlerimportvalidate function in pagemanager/pagemanager.admin.inc.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1546?
CVE-2010-1546 is classified as a critical vulnerability due to its potential for remote code execution by authenticated users.
How do I fix CVE-2010-1546?
To address CVE-2010-1546, update the Chaos Tool Suite (CTools) module to version 6.x-1.4 or later.
Who is affected by CVE-2010-1546?
CVE-2010-1546 affects users with 'administer page manager' privileges in the CTools module versions prior to 6.x-1.4.
What types of attacks does CVE-2010-1546 allow?
CVE-2010-1546 allows attackers to execute arbitrary PHP code via injected input in text areas.
Is CVE-2010-1546 exploitable remotely?
Yes, CVE-2010-1546 can be exploited remotely by authenticated users with specific permissions.