Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j3j6-6mpf-p2c4

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

EPSS

Процентиль: 95%
0.20071
Средний

Связанные уязвимости

ubuntu
около 19 лет назад

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

nvd
около 19 лет назад

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

debian
около 19 лет назад

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_m ...

EPSS

Процентиль: 95%
0.20071
Средний