CVE-2008-6171: Input Validation
includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupalto a version that resolves this vulnerability.Fixed in 5.12 - Upgrade
Upgrade
Drupalto a version that resolves this vulnerability.Fixed in 6.6
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6171?
CVE-2008-6171 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2008-6171?
To fix CVE-2008-6171, upgrade to Drupal version 5.12 or 6.6 or later.
Which versions of Drupal are affected by CVE-2008-6171?
CVE-2008-6171 affects Drupal versions 5.x before 5.12 and 6.x before 6.6.
Can CVE-2008-6171 be exploited remotely?
Yes, CVE-2008-6171 can be exploited remotely by sending crafted HTTP Host headers.
What are the consequences of not patching CVE-2008-6171?
Failing to patch CVE-2008-6171 may allow attackers to include and execute arbitrary files on the server.