Description
Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.
Remediation
References
Related Vulnerabilities
WordPress Plugin Audio Player Cross-Site Scripting (2.0.4.5)
WordPress Plugin GeoDirectory Location Manager Multiple SQL Injection Vulnerabilities (2.1.0.9)
IBM WebSEAL Session Fixation Vulnerability (CVE-2019-4152)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Multiple Vulnerabilities (4.1.2)