PT-2007-1965 · Drupal · Drupal
Publicado
2007-01-26
·
Atualizado
2017-07-29
·
CVE-2007-0505
CVSS v2.0
8.5
Alta
| Vetor | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Drupal Project issue tracking module versions 4.7.0 through 5.x before 20070123
Description
The issue allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.
Recommendations
For versions 4.7.0 through 5.x before 20070123, consider restricting file uploads to only authorized users and validating file extensions to prevent executable files from being uploaded until a fix is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Drupal