Vulnerabilities > Drupal > Aggregation Module > Critical

DATE CVE VULNERABILITY TITLE RISK
2008-07-03 CVE-2008-3001 Code Injection vulnerability in Drupal Aggregation Module
The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed that allows upload of files with arbitrary extensions.
network
drupal CWE-94
critical
9.3