CVE-2012-5653

Publication date

2013-01-03 01:00:00

Family

redhat

State

PUBLISHED

Description

The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.