CVE Database
/

CVE-2010-3092

Back to search

CVE-2010-3092

Published: Sep 21, 2010

Modified: Sep 16, 2024

PUBLISHED

Description

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-2113
vendor-advisory
x_refsource_DEBIAN
42391
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now