Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal 上传模块多个权限许可和访问控制漏洞
Vulnerability Description
Drupal是很著名的开源内容管理平台,仿照了blog程序模式,但比普通的blog更灵活,可以做各种网站的内容管理平台。 Drupal 5.23之前的5.x版本和6.18之前的6.x版本中的上传模块不能在数据库配置中正常地支持case-insensitive(对大小写不敏感)文件名处理,远程认证用户可以通过用相同文件名上传不同文件来绕过预设的文件下载限制。
CVSS Information
N/A
Vulnerability Type
N/A