Release date:
Updated on: 2013-01-22
Affected Systems:
Drupal Live CSS Module 7.x
Drupal Live CSS Module 6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57436
The Live CSS module can present and edit the LESS style sheet in real time.
Live CSS 7. x-2.x allows you to upload files with any extension to a folder in webroot, which can cause arbitrary PHP code execution by uploading malicious PHP scripts. The "administer CSS" permission is required to successfully exploit this vulnerability.
<* Source: Ryan garret
Link: http://drupal.org/node/1890318
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Drupal
------
Drupal has released a Security Bulletin (1890318) and corresponding patches for this purpose:
1890318: SA-CONTRIB-2013-004-Live CSS-Arbitrary Code Execution
Link: http://drupal.org/node/1890318