PT-2006-3663 · Apache+1 · Apache+1

Rgod

·

Published

2006-06-01

·

Updated

2018-10-18

·

CVE-2006-2743

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Drupal versions 4.6.x through 4.6.6 Drupal version 4.7.0
Description The issue arises from improper handling of files with multiple extensions when running on Apache with mod mime. This allows remote attackers to upload, modify, or execute arbitrary files in the files directory.
Recommendations For Drupal versions 4.6.x through 4.6.6, update to version 4.6.7 or later. For Drupal version 4.7.0, consider disabling the file upload feature until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2743
DSA-1125

Affected Products

Apache
Drupal