TE
TechEcho
Home
24h Top
Newest
Best
Ask
Show
Jobs
English
GitHub
Twitter
Home
Drupal RCE via file upload (abc.html.txt, filename.php.gif)
3 points
by
axsharma
over 4 years ago
1 comment
axsharma
over 4 years ago
The vulnerability also tracked as SA-CORE-2020-012, exists due to improper validation of filenames of files uploaded to Drupal websites.<p>E.g. filename.php.txt or filename.html.gif, without an underscore (_) in the extension.