The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x...
Vulnerability Description
The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP that does not support the json_decode function, allows remote attackers to execute arbitrary PHP code via unspecified vectors related to Ajax operations, possibly involving eval injection.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-4446
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122308.html
- https://drupal.org/node/2113317
- https://drupal.org/node/2112785
- http://drupalcode.org/project/context.git/commitdiff/63ef4d9
- http://lists.fedoraproject.org/pipermail/package-announce/2013-November/121433.html
- http://drupalcode.org/project/context.git/commitdiff/d7b4afa
- http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122298.html
- https://drupal.org/node/2112791
More from steven jones
View All →Affected Vendor
steven jones
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.