Drupal – the popular open source content management system – will release patches for several highly critical remote code execution (RCE) bugs that could allow any hacker to take complete control of any compromised page.

We present the three distinct Drupal sections that affect up to 10,000 websites:
1. RESTful Web Services
A popular module used to create REST APIs, which is installed on at least 5,804 websites.
The vulnerability in RESTWS alters the callbacks of the default page so that entities can provide additional functions, allowing attackers to send specially crafted requests that result in arbitrary PHP execution.
2. Coder
A module used for code analysis, which is installed on at least 4,951 websites.
The vulnerability exists in the Coder module which does not properly validate what the user inputs in a script file that has the PHP extension, allowing a malicious unauthorized user to make direct requests to this file to execute arbitrary code.
To exploit the vulnerability, the Coder module does not even need to be enabled. The presence of the module in the file system and being accessible from the Web is enough for an attacker to exploit this flaw.
3. Webform Multiple File Upload
A module used to collect files from website visitors, which is installed on at least 3,076 websites.
The Webform Multiple File Upload contains a faulty remote executable code that could allow an attacker to take over any compromised area using a specially crafted request.
Any visitor to the website could potentially exploit this vulnerability to perform several malicious actions on the site.
