Description
install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified.
Remediation
References
Related Vulnerabilities
WordPress Plugin Yoast SEO Security Bypass (1.4.6)
Microsoft SQL Server Other Vulnerability (CVE-2001-0879)
WordPress Plugin Elementor Website Builder Cross-Site Scripting (2.7.5)
WordPress Plugin Contus HD FLV Player 'uploadVideo.php' Arbitrary File Upload (1.7)
ownCloud Improper Access Control Vulnerability (CVE-2016-9467)