RESTWS alters the default page callbacks for entities to provide additional functionality.

A vulnerability in this approach allows an attacker to send specially crafted requests resulting in arbitrary PHP execution.

There are no mitigating factors. This vulnerability can be exploited by anonymous users.

This vulnerability affects the following application versions:

  • Drupal Module RESTWS 7.x-1.0
  • Drupal Module RESTWS 7.x-1.0-beta1
  • Drupal Module RESTWS 7.x-1.0-beta2
  • Drupal Module RESTWS 7.x-1.1
  • Drupal Module RESTWS 7.x-1.2
  • Drupal Module RESTWS 7.x-1.3
  • Drupal Module RESTWS 7.x-1.4
  • Drupal Module RESTWS 7.x-1.5
  • Drupal Module RESTWS 7.x-1.6
  • Drupal Module RESTWS 7.x-2.0
  • Drupal Module RESTWS 7.x-2.0-alpha1
  • Drupal Module RESTWS 7.x-2.0-alpha2
  • Drupal Module RESTWS 7.x-2.0-alpha3
  • Drupal Module RESTWS 7.x-2.0-alpha4
  • Drupal Module RESTWS 7.x-2.0-alpha5
  • Drupal Module RESTWS 7.x-2.1
  • Drupal Module RESTWS 7.x-2.2
  • Drupal Module RESTWS 7.x-2.3
  • Drupal Module RESTWS 7.x-2.4
  • Drupal Module RESTWS 7.x-2.5

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *