CVE-2010-3092: Medium severity drupal vulnerability
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3092?
CVE-2010-3092 is classified as a medium severity vulnerability affecting specific versions of Drupal.
How do I fix CVE-2010-3092?
To fix CVE-2010-3092, upgrade Drupal to version 5.23 or 6.18 or later, as these versions include the necessary security patches.
Who is affected by CVE-2010-3092?
CVE-2010-3092 affects Drupal versions 5.x before 5.23 and 6.x before 6.18.
What kind of attack is possible due to CVE-2010-3092?
CVE-2010-3092 allows remote authenticated users to bypass file restrictions by uploading files with similar names.
Is there any workaround for CVE-2010-3092 before patching?
There are no specific workarounds for CVE-2010-3092, so upgrading to a patched version is recommended.