CVE-2012-2301: Code Injection
Published Nov 16, 2014
·Updated
The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer product classes" permission to execute arbitrary PHP code via unspecified vectors.
Affected Software
7 affected components
Ubercart Ubercart Drupal=6.x-2.0
Ubercart Ubercart Drupal=6.x-2.1
Ubercart Ubercart Drupal=6.x-2.2
Ubercart Ubercart Drupal=6.x-2.3
Ubercart Ubercart Drupal=6.x-2.4
Ubercart Ubercart Drupal=6.x-2.6
Ubercart Ubercart Drupal=6.x-2.7
Remediation
Patch Available
Patch Available
Event History
Nov 16, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2301?
CVE-2012-2301 has a high severity due to its potential for remote code execution by authenticated users.
2
How do I fix CVE-2012-2301?
To fix CVE-2012-2301, upgrade the Ubercart module to version 6.x-2.8 or later.
3
Who is affected by CVE-2012-2301?
Authenticated users with the "administer product classes" permission on affected versions of the Ubercart module are at risk.
4
What versions of Ubercart are impacted by CVE-2012-2301?
CVE-2012-2301 affects Ubercart versions 6.x-2.0 to 6.x-2.7.
5
What type of vulnerability is CVE-2012-2301?
CVE-2012-2301 is a remote code execution vulnerability that allows unauthorized execution of arbitrary PHP code.