PT-2007-1965 · Drupal · Drupal
Published
2007-01-26
·
Updated
2017-07-29
·
CVE-2007-0505
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Drupal Project issue tracking module versions 4.7.0 through 5.x before 20070123
Description
The issue allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.
Recommendations
For versions 4.7.0 through 5.x before 20070123, consider restricting file uploads to only authorized users and validating file extensions to prevent executable files from being uploaded until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Drupal