CVE-2008-4789
EUVD-2008-476929.10.2008, 15:31
The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| drupal | drupal | 𝑥 ≤ 6.4 |
| drupal | drupal | 6.0 |
| drupal | drupal | 6.0:beta1 |
| drupal | drupal | 6.0:beta2 |
| drupal | drupal | 6.0:beta3 |
| drupal | drupal | 6.0:beta4 |
| drupal | drupal | 6.0:rc-1 |
| drupal | drupal | 6.0:rc-2 |
| drupal | drupal | 6.0:rc-3 |
| drupal | drupal | 6.0:rc-4 |
| drupal | drupal | 6.1 |
| drupal | drupal | 6.2 |
| drupal | drupal | 6.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References