Release date:
Updated on:
Affected Systems:
Drupal Drag & Drop Gallery 6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56936
CVE (CAN) ID: CVE-2012-4479
The Drupal Drag & Drop Gallery module creates an image library node type. You can Drag and Drop images in the local file system to add images to the image library.
Drag & Drop Gallery 6.x and other versions have security vulnerabilities in file processing. This vulnerability allows remote attackers to inject and execute arbitrary SQL commands.
<* Source: Drupal Security Team
Link: http://www.openwall.com/lists/oss-security/2012/10/04/5
Http://drupal.org/node/1679442
*>
Suggestion:
--------------------------------------------------------------------------------
Temporary solution:
If you cannot install or upgrade the patch immediately, NSFOCUS recommends that you take the following measures to reduce the threat:
* Disable the Drag & Drop Gallery module.
Vendor patch:
Drupal
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://drupal.org/project/dragdrop_gallery