Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-4472

Опубликовано: 30 нояб. 2012
Источник: nvd
CVSS2: 5.1
EPSS Низкий

Описание

Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the directory specified by the filedir parameter.

Комментарий

Per: http://cwe.mitre.org/data/definitions/434.html 'CWE-434: Unrestricted Upload of File with Dangerous Type'

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:david_alkire:drag_\&_drop_gallery:*:*:*:*:*:*:*:*
Версия до 6.x-1.5 (включая)
cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*

EPSS

Процентиль: 71%
0.00686
Низкий

5.1 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
около 3 лет назад

Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the directory specified by the filedir parameter.

EPSS

Процентиль: 71%
0.00686
Низкий

5.1 Medium

CVSS2

Дефекты

NVD-CWE-Other