Описание
Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the directory specified by the filedir parameter.
Комментарий
Per: http://cwe.mitre.org/data/definitions/434.html 'CWE-434: Unrestricted Upload of File with Dangerous Type'
Ссылки
- PatchVendor Advisory
- Vendor Advisory
- Exploit
- PatchVendor Advisory
- Vendor Advisory
- Exploit
Уязвимые конфигурации
Одновременно
EPSS
5.1 Medium
CVSS2
Дефекты
Связанные уязвимости
Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the directory specified by the filedir parameter.
EPSS
5.1 Medium
CVSS2