Description
The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."
Remediation
References
Related Vulnerabilities
MODX Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-7321)
Apache HTTP Server CVE-2012-0053 Vulnerability (CVE-2012-0053)
WordPress Plugin Backup Migration Information Disclosure (1.3.5)
JBoss Application Server Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-3609)