The Ubercart module for Drupal is prone to a cross-site-scripting vulnerability, a local information-disclosure vulnerability and a remote PHP-code-execution vulnerability.
Credit:
The original article can be found at: http://www.securityfocus.com/bid/53251
The information has been provided by Shaun Dychko, Lee Rowlands and Dave Long.
Vulnerable Systems:
* Drupal Ubercart 7.x-3.0 and prior
Attackers can exploit these issues to execute arbitrary PHP code in the context of the webserver, obtain sensitive information, and steal cookie-based authentication credentials from legitimate users of the site. Other attacks are also possible.
Vendor Status:
Vendor as issued an updated vulnerability.