When user profile pictures were enabled, the default user profile validation function would be bypassed, possibly allowing invalid user names or e-mail addresses to be submitted.
Part of security release SA-CORE-2009-001
This vulnerability affects the following application versions:
- Drupal 6.0
- Drupal 6.1
- Drupal 6.2
- Drupal 6.3
- Drupal 6.4
- Drupal 6.5
- Drupal 6.6
- Drupal 6.7
- Drupal 6.8