VYPR

core upload module

by Drupal

CVEs (2)

  • CVE-2008-4790Oct 29, 2008
    risk 0.00cvss —epss 0.01

    The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors.

  • CVE-2008-3745Aug 27, 2008
    risk 0.00cvss —epss 0.01

    The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download unauthorized attachments via unspecified vectors.