CVE-2008-0569

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
05/02/2008
Last modified:
09/04/2025

Description

The Comment Upload 4.7.x before 4.7.x-0.1 and 5.x before 5.x-0.1 module for Drupal does not properly use functions in the upload module, which allows remote attackers to bypass upload validation, and upload arbitrary files and possibly execute arbitrary code, via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:drupal:comment_upload_module:4.7:*:*:*:*:*:*:*
cpe:2.3:a:drupal:comment_upload_module:5.0:*:*:*:*:*:*:*