Server side template injection In drupal/core
Description
Drupal arbitrary code execution Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 6.38 | ||
packagist | 6.38 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6.