Apache · Apache · CVE-2006-2831
**Name of the Vulnerable Software and Affected Versions**
Drupal versions 4.6.x through 4.6.7
Drupal versions 4.7.x through 4.7.1
**Description**
The issue allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, under certain Apache configurations, such as when FileInfo overrides are disabled within .htaccess.
**Recommendations**
For Drupal versions 4.6.x through 4.6.7, update to version 4.6.8 or later.
For Drupal versions 4.7.x through 4.7.1, update to version 4.7.2 or later.