PT-2010-4539 · Drupal · Drupal

Steffen Joeris

·

Publicado

2010-09-21

·

Atualizado

2010-09-22

·

CVE-2010-3092

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal versions 5.x prior to 5.23 Drupal versions 6.x prior to 6.18
Description The issue arises from the upload module's improper handling of case-insensitive filename handling in a database configuration. This allows remote authenticated users to bypass intended restrictions on downloading a file by uploading a different file with a similar name.
Recommendations For Drupal versions 5.x prior to 5.23, update to version 5.23 or later. For Drupal versions 6.x prior to 6.18, update to version 6.18 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3092
DSA-2113-1

Produtos afetados

Drupal