[SA-CONTRIB-2016-040] Specially crafted requests allow arbitrary PHP execution
RESTWS alters the default page callbacks for entities to provide additional functionality.
A vulnerability in this approach allows an attacker to send specially crafted requests resulting in arbitrary PHP execution.
There are no mitigating factors. This vulnerability can be exploited by anonymous users.
This vulnerability affects the following application versions:
- Drupal Module RESTWS 7.x-1.0
- Drupal Module RESTWS 7.x-1.0-beta1
- Drupal Module RESTWS 7.x-1.0-beta2
- Drupal Module RESTWS 7.x-1.1
- Drupal Module RESTWS 7.x-1.2
- Drupal Module RESTWS 7.x-1.3
- Drupal Module RESTWS 7.x-1.4
- Drupal Module RESTWS 7.x-1.5
- Drupal Module RESTWS 7.x-1.6
- Drupal Module RESTWS 7.x-2.0
- Drupal Module RESTWS 7.x-2.0-alpha1
- Drupal Module RESTWS 7.x-2.0-alpha2
- Drupal Module RESTWS 7.x-2.0-alpha3
- Drupal Module RESTWS 7.x-2.0-alpha4
- Drupal Module RESTWS 7.x-2.0-alpha5
- Drupal Module RESTWS 7.x-2.1
- Drupal Module RESTWS 7.x-2.2
- Drupal Module RESTWS 7.x-2.3
- Drupal Module RESTWS 7.x-2.4
- Drupal Module RESTWS 7.x-2.5