CVE-2006-2743
medium · 5.1Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.
5.1
CVSS
11.1%
EPSS (exploit prob.)
96th
EPSS percentile
2006-06-01
Published
AV:N/AC:H/Au:N/C:P/I:P/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| drupal | drupal | 4.6 |
| drupal | drupal | 4.6.0 |
| drupal | drupal | 4.6.1 |
| drupal | drupal | 4.6.2 |
| drupal | drupal | 4.6.3 |
| drupal | drupal | 4.6.4 |
| drupal | drupal | 4.6.5 |
| drupal | drupal | 4.6.6 |
| drupal | drupal | 4.7.0 |
Check a specific version with /api/v1/cve/match.
References
- http://drupal.org/node/65409
- http://secunia.com/advisories/20140
- http://secunia.com/advisories/21244
- http://www.debian.org/security/2006/dsa-1125
- http://www.securityfocus.com/archive/1/435794/100/0/threaded
- http://www.securityfocus.com/bid/18245
- http://www.vupen.com/english/advisories/2006/1975
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26655
- https://www.exploit-db.com/exploits/1821
- http://drupal.org/node/65409
- http://secunia.com/advisories/20140
- http://secunia.com/advisories/21244
- http://www.debian.org/security/2006/dsa-1125
- http://www.securityfocus.com/archive/1/435794/100/0/threaded
- http://www.securityfocus.com/bid/18245
- http://www.vupen.com/english/advisories/2006/1975
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26655
- https://www.exploit-db.com/exploits/1821
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-2743