Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j3j6-6mpf-p2c4

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

EPSS

Процентиль: 95%
0.22706
Средний

Связанные уязвимости

ubuntu
больше 19 лет назад

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

nvd
больше 19 лет назад

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

debian
больше 19 лет назад

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_m ...

EPSS

Процентиль: 95%
0.22706
Средний