Description
The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.
Remediation
References
Related Vulnerabilities
MediaWiki Other Vulnerability (CVE-2023-37300)
MySQL CVE-2014-4214 Vulnerability (CVE-2014-4214)
WordPress Plugin Disqus Comment System Multiple Cross-Site Request Forgery Vulnerabilities (2.77)
CubeCart Improper Authentication Vulnerability (CVE-2014-2341)
Oracle Application Server Other Vulnerability (CVE-2002-0560)