Drupal Fill PDF Module Security Bypass and Arbitrary Code Execution Vulnerabilities
16 Jun. 2012
Summary
The Fill PDF module for Drupal is prone to a security-bypass vulnerability and an arbitrary-code-execution vulnerability because the application fails to sufficiently sanitize user-supplied data.
Credit:
The original article can be found at: http://www.securityfocus.com/bid/51288
The information has been provided by Christian Johansson and Liam Morland .
Vulnerable Systems:
*Drupal Fill PDF 7.x-1.1 and prior
Attackers can exploit these issues to execute arbitrary code in the context of the webserver and bypass security restrictions to perform unauthorized actions. Other attacks are also possible.
Vendor Status:
Currently we are not aware of any vendor-supplied patches.