Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3171

Опубликовано: 12 апр. 2016
Источник: debian
EPSS Низкий

Описание

Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
drupal7not-affectedpackage
drupal6removedpackage
drupal6end-of-lifesqueezepackage

Примечания

  • https://www.drupal.org/SA-CORE-2016-001

  • https://www.openwall.com/lists/oss-security/2016/02/24/19

EPSS

Процентиль: 91%
0.07448
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 9 лет назад

Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.

CVSS3: 8.1
nvd
больше 9 лет назад

Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.

CVSS3: 8.1
github
около 3 лет назад

Drupal arbitrary code execution

EPSS

Процентиль: 91%
0.07448
Низкий