CVE-2016-3171

high
Published 2016-04-12 · Modified 2024-04-23
CVSS v3
8.1
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
6.8
VIR risk
8.1

Description

Drupal arbitrary code execution

Predictions

Exploit likelihood
88%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.drupal.org/SA-CORE-2016-001

OS impact

OSVersionStatusFixed in
debian debian7.0affected
debian debian8.0affected

Package impact

EcosystemPackageVulnerableFixed
php Packagistdrupal/core>=6.0,<6.386.38
php Packagistdrupal/drupal>=6.0,<6.386.38

Application impact

VendorProductVersionsFixed
phpphp{"endIncluding":"5.4.44"}
phpphp5.5.0
phpphp5.5.1
phpphp5.5.2
phpphp5.5.10
phpphp5.5.11
phpphp5.5.12
phpphp5.5.13
phpphp5.5.14
phpphp5.5.18
phpphp5.5.19
phpphp5.5.20
phpphp5.5.21
phpphp5.5.22
phpphp5.5.23
phpphp5.5.24
phpphp5.5.25
phpphp5.5.26
phpphp5.5.27
phpphp5.5.28
phpphp5.6.0
phpphp5.6.1
phpphp5.6.2
phpphp5.6.3
phpphp5.6.4
phpphp5.6.5
phpphp5.6.6
phpphp5.6.7
phpphp5.6.8
phpphp5.6.9
phpphp5.6.10
phpphp5.6.11
phpphp5.6.12
drupaldrupal6.0
drupaldrupal6.1
drupaldrupal6.2
drupaldrupal6.3
drupaldrupal6.4
drupaldrupal6.5
drupaldrupal6.6
drupaldrupal6.7
drupaldrupal6.8
drupaldrupal6.9
drupaldrupal6.10
drupaldrupal6.11
drupaldrupal6.12
drupaldrupal6.13
drupaldrupal6.14
drupaldrupal6.15
drupaldrupal6.16
drupaldrupal6.17
drupaldrupal6.18
drupaldrupal6.19
drupaldrupal6.20
drupaldrupal6.21
drupaldrupal6.22
drupaldrupal6.23
drupaldrupal6.24
drupaldrupal6.25
drupaldrupal6.26
drupaldrupal6.27
drupaldrupal6.28
drupaldrupal6.29
drupaldrupal6.30
drupaldrupal6.31
drupaldrupal6.32
drupaldrupal6.33
drupaldrupal6.34
drupaldrupal6.35
drupaldrupal6.36
drupaldrupal6.37

References

CWEs

CWE-19

Verify integrity in audit chain (admin only). AS-IS.