7.5
CVSSv2

CVE-2006-2831

Published: 06/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Drupal 4.6.x prior to 4.6.8 and 4.7.x prior to 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote malicious users to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal 4.6.0

drupal drupal 4.6.1

drupal drupal 4.7.1

drupal drupal 4.6

drupal drupal 4.6.6

drupal drupal 4.6.7

drupal drupal 4.7.0

drupal drupal 4.6.2

drupal drupal 4.6.3

drupal drupal 4.6.4

drupal drupal 4.6.5

Vendor Advisories

The Drupal update in DSA 1125 contained a regression This update corrects this flaw For completeness, the original advisory text below: Several remote vulnerabilities have been discovered in the Drupal web site platform, which may lead to the execution of arbitrary web script The Common Vulnerabilities and Exposures project identifies the follow ...