← Back

CVE-2012-6065

nvd nist
Published: Dec 3, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.6
Vector
AV:N/AC:H/Au:S/C:P/I:P/A:P
Exploitability: 3.9 / Impact: 6.4
Source: NVD

Description

The OM Maximenu module 6.x-1.43 and earlier for Drupal, when the "Title has PHP" option is enabled, allows remote authenticated users with the "Administer OM Maximenu" permission to execute arbitrary PHP code via a "Link Title," a different vulnerability than CVE-2012-5553.

Affected (52)

Om Maximenu
Configuration A
52 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Daniel Honrade
Up to 6.x-1.43
Version 6.x-1.0
Version 6.x-1.0 rc1
Version 6.x-1.0 rc2
Version 6.x-1.0 rc3
Version 6.x-1.0 rc4
Version 6.x-1.0 rc5
Version 6.x-1.0 rc6
Version 6.x-1.0 rc7
Version 6.x-1.10
Version 6.x-1.11
Version 6.x-1.12
Version 6.x-1.13
Version 6.x-1.14
Version 6.x-1.15
Version 6.x-1.16
Version 6.x-1.17
Version 6.x-1.18
Version 6.x-1.19
Version 6.x-1.1
Version 6.x-1.20
Version 6.x-1.21
Version 6.x-1.22
Version 6.x-1.23
Version 6.x-1.24
Version 6.x-1.25
Version 6.x-1.26
Version 6.x-1.27
Version 6.x-1.28
Version 6.x-1.29
Version 6.x-1.2
Version 6.x-1.30
Version 6.x-1.31
Version 6.x-1.32
Version 6.x-1.33
Version 6.x-1.34
Version 6.x-1.35
Version 6.x-1.36
Version 6.x-1.37
Version 6.x-1.38
Version 6.x-1.39
Version 6.x-1.3
Version 6.x-1.40
Version 6.x-1.41
Version 6.x-1.42
Version 6.x-1.4
Version 6.x-1.5
Version 6.x-1.6
Version 6.x-1.7
Version 6.x-1.8
Version 6.x-1.9
Version 6.x-1.x dev
Running on/withPlatform Versions
Drupal
Drupal
All versions

References (6)

Source: cve@mitre.org
Patch
Source: cve@mitre.org
Patch
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.