System compromise in Drupal Live CSS

Posted: January 22, 2013 in Vulnerabilities
Tags: , ,

Drupal logo

System compromise

Vulnerability: System compromise in Drupal Live CSS

Danger: Average
Patch: Yes
Number of vulnerabilities: 1

Vector of operation: Remote
Impact: System Compromise

Affected products: Drupal Live CSS Module 6.x
Drupal Live CSS Module 7.x

Affected versions: Live CSS module for Drupal 6.x-2.1, perhaps the only one.
Live CSS module for Drupal 7.x-2.7, perhaps the only one.


The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability is caused due to insufficient checks for file uploads. A remote user can upload a file with an arbitrary extension containing PHP code and execute it on the system.

Successful exploitation requires that you must have permission ‘administer CSS’.

Manufacturer :

Solution: Install the latest version from the manufacturer.


Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s