PT-2006-3663 · Apache+1 · Apache+1

Rgod

·

Publicado

2006-06-01

·

Atualizado

2018-10-18

·

CVE-2006-2743

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Drupal versions 4.6.x through 4.6.6 Drupal version 4.7.0
Description The issue arises from improper handling of files with multiple extensions when running on Apache with mod mime. This allows remote attackers to upload, modify, or execute arbitrary files in the files directory.
Recommendations For Drupal versions 4.6.x through 4.6.6, update to version 4.6.7 or later. For Drupal version 4.7.0, consider disabling the file upload feature until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2743
DSA-1125

Produtos afetados

Apache
Drupal