Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-5653

Опубликовано: 03 янв. 2013
Источник: debian
EPSS Низкий

Описание

The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
drupal6removedpackage
drupal7fixed7.14-1.2package

Примечания

  • http://drupal.org/SA-CORE-2012-004

EPSS

Процентиль: 73%
0.00829
Низкий

Связанные уязвимости

ubuntu
больше 12 лет назад

The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.

nvd
больше 12 лет назад

The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.

github
около 3 лет назад

The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.

EPSS

Процентиль: 73%
0.00829
Низкий