CVE-2012-5537
03.12.2012, 21:55
The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission to inject arbitrary PHP code into the scheduling form, which is later executed by cron.
Vendor | Product | Version |
---|---|---|
simplenews_scheduler_project | simplenews_scheduler | 6.x-2.0:x |
simplenews_scheduler_project | simplenews_scheduler | 6.x-2.0:x |
simplenews_scheduler_project | simplenews_scheduler | 6.x-2.0:x |
simplenews_scheduler_project | simplenews_scheduler | 6.x-2.0:x |
simplenews_scheduler_project | simplenews_scheduler | 6.x-2.1:x |
simplenews_scheduler_project | simplenews_scheduler | 6.x-2.2:x |
simplenews_scheduler_project | simplenews_scheduler | 6.x-2.3:x |
simplenews_scheduler_project | simplenews_scheduler | 6.x-2.x:x |
𝑥
= Vulnerable software versions