First published: Tue Jun 06 2006(Updated: )
Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal | =4.6.0 | |
Drupal | =4.6 | |
Drupal | =4.6.5 | |
Drupal | =4.6.2 | |
Drupal | =4.6.3 | |
Drupal | =4.6.4 | |
Drupal | =4.7.0 | |
Drupal | =4.6.7 | |
Drupal | =4.6.1 | |
Drupal | =4.7.1 | |
Drupal | =4.6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2831 is considered to have a high severity due to the potential for remote code execution.
To fix CVE-2006-2831, you should upgrade to Drupal version 4.6.8 or 4.7.2 or later.
CVE-2006-2831 affects Drupal versions 4.6.x before 4.6.8 and 4.7.x before 4.7.2.
CVE-2006-2831 can be exploited when certain Apache configurations, such as disabled FileInfo overrides, are in place.
CVE-2006-2831 facilitates remote code execution attacks through the uploading of files with multiple extensions.