CVE-2014-5170

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
29/03/2018
Last modified:
27/04/2018

Description

The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveraging failure to update .htaccess file contents after SA-CORE-2013-003.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:drupal:storage_api:7.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:drupal:storage_api:7.x-1.1:*:*:*:*:*:*:*
cpe:2.3:a:drupal:storage_api:7.x-1.2:*:*:*:*:*:*:*
cpe:2.3:a:drupal:storage_api:7.x-1.3:*:*:*:*:*:*:*
cpe:2.3:a:drupal:storage_api:7.x-1.4:*:*:*:*:*:*:*
cpe:2.3:a:drupal:storage_api:7.x-1.5:*:*:*:*:*:*:*
cpe:2.3:a:drupal:storage_api:7.x-1.x-dev:*:*:*:*:*:*:*