Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g749-r93q-q2rq

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

EPSS

Процентиль: 39%
0.00173
Низкий

Связанные уязвимости

ubuntu
больше 14 лет назад

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

nvd
больше 14 лет назад

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

debian
больше 14 лет назад

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does n ...

EPSS

Процентиль: 39%
0.00173
Низкий