TE
科技回声
首页
24小时热榜
最新
最佳
问答
展示
工作
中文
GitHub
Twitter
首页
Drupal RCE via file upload (abc.html.txt, filename.php.gif)
3 点
作者
axsharma
超过 4 年前
1 comment
axsharma
超过 4 年前
The vulnerability also tracked as SA-CORE-2020-012, exists due to improper validation of filenames of files uploaded to Drupal websites.<p>E.g. filename.php.txt or filename.html.gif, without an underscore (_) in the extension.