Unrated severityNVD Advisory· Published Aug 27, 2008· Updated Jun 16, 2026
CVE-2008-3742
CVE-2008-3742
Description
Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, which is not validated.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16cpe:2.3:a:drupal:drupal:5.0:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:drupal:drupal:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:5.1:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:5.2:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:5.3:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:5.4:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:5.5:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:5.6:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:5.7:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:5.8:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:5.9:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:6.1:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:6.2:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:6.3:*:*:*:*:*:*:*
- (no CPE)range: 5.x before 5.10, 6.x before 6.4
Patches
Vulnerability mechanics
References
9- drupal.org/node/295053nvd
- secunia.com/advisories/31462nvd
- secunia.com/advisories/31825nvd
- www.securityfocus.com/bid/30689nvd
- www.vupen.com/english/advisories/2008/2392nvd
- bugzilla.redhat.com/show_bug.cginvd
- exchange.xforce.ibmcloud.com/vulnerabilities/44447nvd
- www.redhat.com/archives/fedora-package-announce/2008-September/msg00259.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2008-September/msg00508.htmlnvd
News mentions
0No linked articles in our index yet.