CVE-2012-5653
Description
The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.
- CVSS Version 2.0
nvd
CVE ID: CVE-2012-5653
Base Score: 6.0
Base Severity: MEDIUM
Vector String:AV:N/AC:M/Au:S/C:P/I:P/A:P
Refrence: NVD