File uploads with certain extensions were not correctly processed by the File API. This may lead to the creation of files that were executable by Apache. The .htaccess that was saved into the files directory by Drupal should normally prevent execution. The files were only executable when the server was configured to ignore the directives in the .htaccess file.
Part of security release SA-CORE-2009-008
This vulnerability affects the following application versions:
- Drupal 6.0
- Drupal 6.1
- Drupal 6.2
- Drupal 6.3
- Drupal 6.4
- Drupal 6.5
- Drupal 6.6
- Drupal 6.7
- Drupal 6.8
- Drupal 6.9
- Drupal 6.10
- Drupal 6.11
- Drupal 6.12
- Drupal 6.13