PT-2013-1824 · Drupal · Drupal

Forest Monsen

·

Published

2013-01-03

·

Updated

2017-08-29

·

CVE-2012-5653

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Drupal versions 6.x before 6.27 Drupal versions 7.x before 7.18
Description The issue concerns the file upload feature, which allows remote authenticated users to bypass a protection mechanism. This can be achieved by including a null byte in a file name, enabling the execution of arbitrary PHP code.
Recommendations For versions 6.x before 6.27, update to version 6.27 or later. For versions 7.x before 7.18, update to version 7.18 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-5653
DSA-2776-1

Affected Products

Drupal