CVE Vulnerabilities

CVE-2008-6171

Published: Feb 19, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for IP-based virtual hosts, allows remote attackers to include and execute arbitrary files via the HTTP Host header.

Affected Software

NameVendorStart VersionEnd Version
DrupalDrupal5.0 (including)5.0 (including)
DrupalDrupal5.1 (including)5.1 (including)
DrupalDrupal5.2 (including)5.2 (including)
DrupalDrupal5.3 (including)5.3 (including)
DrupalDrupal5.4 (including)5.4 (including)
DrupalDrupal5.5 (including)5.5 (including)
DrupalDrupal5.6 (including)5.6 (including)
DrupalDrupal5.7 (including)5.7 (including)
DrupalDrupal5.8 (including)5.8 (including)
DrupalDrupal5.9 (including)5.9 (including)
DrupalDrupal5.10 (including)5.10 (including)
DrupalDrupal5.11 (including)5.11 (including)
DrupalDrupal6.0 (including)6.0 (including)
DrupalDrupal6.1 (including)6.1 (including)
DrupalDrupal6.2 (including)6.2 (including)
DrupalDrupal6.3 (including)6.3 (including)
DrupalDrupal6.4 (including)6.4 (including)
DrupalDrupal6.5 (including)6.5 (including)
Drupal5Ubuntugutsy*
Drupal5Ubuntuhardy*
Drupal5Ubuntuintrepid*
Drupal5Ubuntuupstream*
Drupal6Ubuntuupstream*

References