Vulnerabilities > CVE-2012-4472 - Unspecified vulnerability in David Alkire Drag & Drop Gallery 6.X1.5
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the directory specified by the filedir parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
Application | 1 |
References
- http://drupal.org/node/1679442
- http://drupal.org/node/1679442
- http://secunia.com/advisories/49698
- http://secunia.com/advisories/49698
- http://www.opensyscom.fr/Actualites/drupal-modules-drag-a-drop-gallery-arbitrary-file-upload-vulnerability.html
- http://www.opensyscom.fr/Actualites/drupal-modules-drag-a-drop-gallery-arbitrary-file-upload-vulnerability.html
- http://www.openwall.com/lists/oss-security/2012/10/04/5
- http://www.openwall.com/lists/oss-security/2012/10/04/5
- http://www.securityfocus.com/bid/54380
- http://www.securityfocus.com/bid/54380