The Upload module in Drupal 6 contained privilege escalation vulnerabilities for users with the “upload files” permission. This cuould lead to users being able to edit nodes which they were normally not allowed to, delete any file to which the webserver had sufficient rights, and download attachments of nodes to which they had no access. Harmful files may also be uploaded via cross site request forgeries (CSRF).
Part of security release SA-2008-047
This vulnerability affects the following application versions:
- Drupal 6.0
- Drupal 6.1
- Drupal 6.2
- Drupal 6.3