CVE-2008-4789
29.10.2008, 15:31
The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."Enginsight
Vendor | Product | Version |
---|---|---|
drupal | drupal | 𝑥 ≤ 6.4 |
drupal | drupal | 6.0 |
drupal | drupal | 6.0:beta1 |
drupal | drupal | 6.0:beta2 |
drupal | drupal | 6.0:beta3 |
drupal | drupal | 6.0:beta4 |
drupal | drupal | 6.0:rc-1 |
drupal | drupal | 6.0:rc-2 |
drupal | drupal | 6.0:rc-3 |
drupal | drupal | 6.0:rc-4 |
drupal | drupal | 6.1 |
drupal | drupal | 6.2 |
drupal | drupal | 6.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References