On a server configured for IP-based virtual hosts, Drupal may be caused to include and execute specifically named files outside of its root directory.
Part of security release SA-2008-067
This vulnerability affects the following application versions:
- Drupal 6.0
- Drupal 6.1
- Drupal 6.2
- Drupal 6.3
- Drupal 6.4
- Drupal 6.5