TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Drupal RCE via file upload (abc.html.txt, filename.php.gif)

3 pointsby axsharmaover 4 years ago

1 comment

axsharmaover 4 years ago
The vulnerability also tracked as SA-CORE-2020-012, exists due to improper validation of filenames of files uploaded to Drupal websites.<p>E.g. filename.php.txt or filename.html.gif, without an underscore (_) in the extension.