PublicDate: 2006-06-01 10:02:00 UTC Candidate: CVE-2006-2743 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2743 Description: Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_drupal: ignored (reached end-of-life) edgy_drupal: released (4.5.8-2) feisty_drupal: needed (reached end-of-life) gutsy_drupal: DNE hardy_drupal: DNE intrepid_drupal: DNE jaunty_drupal: DNE karmic_drupal: DNE devel_drupal: DNE upstream_drupal: needs-triage