Description
Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.
Remediation
References
Related Vulnerabilities
MySQL Uncontrolled Resource Consumption Vulnerability (CVE-2020-11080)
WordPress Plugin All-in-One Event Calendar Cross-Site Scripting (2.5.38)
WordPress Plugin Simple Link Directory PHP Object Injection (5.5.0)
WordPress Plugin IgniteUp-Coming Soon and Maintenance Mode Multiple Vulnerabilities (3.4)