First published: Wed Oct 29 2008(Updated: )
The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | =6.0-beta2 | |
Drupal Drupal | =6.2 | |
Drupal Drupal | =6.0-beta4 | |
Drupal Drupal | =6.0-rc-2 | |
Drupal Drupal | =6.0-beta1 | |
Drupal Drupal | =6.0-rc-1 | |
Drupal Drupal | =6.0-rc-3 | |
Drupal Drupal | =6.1 | |
Drupal Drupal | <=6.4 | |
Drupal Drupal | =6.0 | |
Drupal Drupal | =6.0-rc-4 | |
Drupal Drupal | =6.0-beta3 | |
Drupal Drupal | =6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.