MEDIUM
The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP that does not support the json_decode function, allows remote attackers to execute arbitrary PHP code via unspecified vectors related to Ajax operations, possibly involving eval injection
Published Dec 7, 2013
6.8
MEDIUMCVSS 2.0
EPSS 1.53%
Description
The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP that does not support the json_decode function, allows remote attackers to execute arbitrary PHP code via unspecified vectors related to Ajax operations, possibly involving eval injection.
Affected products
No data.
AND
OR
- 6.x-2.0
- 6.x-2.0
- 6.x-2.0
- 6.x-2.0
- 6.x-2.0
- 6.x-2.0
- 6.x-2.0
- 6.x-2.0
- 6.x-2.0
- 6.x-2.0
- 6.x-2.0
- 6.x-2.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.1
- 6.x-3.x
- 7.x-3.0
- 7.x-3.0
- 7.x-3.0
- 7.x-3.0
- 7.x-3.0
- 7.x-3.0
- 7.x-3.0
- 7.x-3.0
- 7.x-3.0
- 7.x-3.0
- 7.x-3.x
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://drupalcode.org/project/context.git/commitdiff/63ef4d9 x_refsource_CONFIRMPatch
- http://drupalcode.org/project/context.git/commitdiff/d7b4afa x_refsource_CONFIRMPatch
- http://lists.fedoraproject.org/pipermail/package-announce/2013-November/121433.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122298.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122308.html vendor-advisoryx_refsource_FEDORA
- https://drupal.org/node/2112785 x_refsource_CONFIRMPatch
- https://drupal.org/node/2112791 x_refsource_CONFIRMPatch
- https://drupal.org/node/2113317 x_refsource_CONFIRMPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-4317 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://drupalcode.org/project/context.git/commitdiff/63ef4d9 | x_refsource_CONFIRMPatch | |
| http://drupalcode.org/project/context.git/commitdiff/d7b4afa | x_refsource_CONFIRMPatch | |
| http://lists.fedoraproject.org/pipermail/package-announce/2013-November/121433.html | vendor-advisoryx_refsource_FEDORA | |
| http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122298.html | vendor-advisoryx_refsource_FEDORA | |
| http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122308.html | vendor-advisoryx_refsource_FEDORA | |
| https://drupal.org/node/2112785 | x_refsource_CONFIRMPatch | |
| https://drupal.org/node/2112791 | x_refsource_CONFIRMPatch | |
| https://drupal.org/node/2113317 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-4317 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 7, 2013
Updated Aug 6, 2024
Reserved Jun 12, 2013
Link CVE-2013-4446
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-4317 Assigner redhat
Published Dec 7, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2013-4317