CVE-2008-3001: Code Injection
Published Jul 3, 2008
·Updated
The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed that allows upload of files with arbitrary extensions.
Affected Software
8 affected components
Drupal Aggregation module=5
Drupal Aggregation module=3.2
Drupal Aggregation module=4.0
Drupal Aggregation module=4.1
Drupal Aggregation module=4.3
Drupal Aggregation module=4.2
Drupal Aggregation module=3.1
Drupal Aggregation module=3.0
Remediation
Patch Available
Event History
Jul 3, 2008
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3001?
CVE-2008-3001 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2008-3001?
To fix CVE-2008-3001, you should update the Aggregation module to version 5.x-4.4 or later.
3
Which versions of the Aggregation module are affected by CVE-2008-3001?
CVE-2008-3001 affects Aggregation module versions 5.x before 5.x-4.4, 4.x, and 3.x before 3.x-4.4.
4
What does CVE-2008-3001 allow attackers to do?
CVE-2008-3001 allows attackers to upload files with arbitrary extensions and potentially execute arbitrary code.
5
Is CVE-2008-3001 specific to any CMS?
Yes, CVE-2008-3001 specifically affects the Drupal content management system and its Aggregation module.