CVE-2008-4790
29.10.2008, 15:31
The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors.Enginsight
Vendor | Product | Version |
---|---|---|
drupal | drupal | 𝑥 ≤ 5.10 |
drupal | drupal | 5.0 |
drupal | drupal | 5.0:beta1 |
drupal | drupal | 5.0:beta2 |
drupal | drupal | 5.0:rc1 |
drupal | drupal | 5.0:rc2 |
drupal | drupal | 5.1 |
drupal | drupal | 5.2 |
drupal | drupal | 5.3 |
drupal | drupal | 5.4 |
drupal | drupal | 5.5 |
drupal | drupal | 5.6 |
drupal | drupal | 5.7 |
drupal | drupal | 5.8 |
drupal | drupal | 5.9 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References