Drupal core’s file upload feature blocks the upload of many files that could be executed on the server by munging the filename. A malicious user could name a file in a manner that bypasses this munging of the filename in Drupal’s input validation.

Part of security release SA-CORE-2012-004

This vulnerability affects the following application versions:

  • Drupal 6.0
  • Drupal 6.1
  • Drupal 6.2
  • Drupal 6.6
  • Drupal 6.7
  • Drupal 6.8
  • Drupal 6.9
  • Drupal 6.10
  • Drupal 6.11
  • Drupal 6.12
  • Drupal 6.13
  • Drupal 6.14
  • Drupal 6.15
  • Drupal 6.16
  • Drupal 6.17
  • Drupal 6.18
  • Drupal 6.19
  • Drupal 6.20
  • Drupal 6.21
  • Drupal 6.22
  • Drupal 6.23
  • Drupal 6.24
  • Drupal 6.25
  • Drupal 6.26

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *