CVE Vulnerabilities

CVE-2013-0224

Published: Mar 19, 2013 | Modified: Mar 21, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Video module 7.x-2.x before 7.x-2.9 for Drupal, when using the FFmpeg transcoder, allows local users to execute arbitrary PHP code by modifying a temporary PHP file.

Affected Software

Name Vendor Start Version End Version
Video Video_project 7.x-2.0-alpha1 (including) 7.x-2.0-alpha1 (including)
Video Video_project 7.x-2.0-alpha2 (including) 7.x-2.0-alpha2 (including)
Video Video_project 7.x-2.0-alpha3 (including) 7.x-2.0-alpha3 (including)
Video Video_project 7.x-2.0-alpha4 (including) 7.x-2.0-alpha4 (including)
Video Video_project 7.x-2.0-alpha5 (including) 7.x-2.0-alpha5 (including)
Video Video_project 7.x-2.0-alpha6 (including) 7.x-2.0-alpha6 (including)
Video Video_project 7.x-2.1-alpha1 (including) 7.x-2.1-alpha1 (including)
Video Video_project 7.x-2.1-alpha2 (including) 7.x-2.1-alpha2 (including)
Video Video_project 7.x-2.1-alpha3 (including) 7.x-2.1-alpha3 (including)
Video Video_project 7.x-2.2 (including) 7.x-2.2 (including)
Video Video_project 7.x-2.2-beta1 (including) 7.x-2.2-beta1 (including)
Video Video_project 7.x-2.2-beta2 (including) 7.x-2.2-beta2 (including)
Video Video_project 7.x-2.2-beta3 (including) 7.x-2.2-beta3 (including)
Video Video_project 7.x-2.2-beta4 (including) 7.x-2.2-beta4 (including)
Video Video_project 7.x-2.2-beta5 (including) 7.x-2.2-beta5 (including)
Video Video_project 7.x-2.3 (including) 7.x-2.3 (including)
Video Video_project 7.x-2.4 (including) 7.x-2.4 (including)
Video Video_project 7.x-2.5 (including) 7.x-2.5 (including)
Video Video_project 7.x-2.6 (including) 7.x-2.6 (including)
Video Video_project 7.x-2.7 (including) 7.x-2.7 (including)
Video Video_project 7.x-2.8 (including) 7.x-2.8 (including)
Video Video_project 7.x-2.x-dev (including) 7.x-2.x-dev (including)

References