Security Advisory

CVE-2008-3001

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-07-03 17:47:00
Last updated 2024-08-07 09:21:35
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed that allows upload of files with arbitrary extensions.