includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for IP-based virtual hosts, allows remote attackers to include and execute arbitrary files via the HTTP Host header.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Drupal | Drupal | 5.10 | 5.10 |
Drupal | Drupal | 5.4 | 5.4 |
Drupal | Drupal | 6.2 | 6.2 |
Drupal | Drupal | 5.2 | 5.2 |
Drupal | Drupal | 5.7 | 5.7 |
Drupal | Drupal | 6.4 | 6.4 |
Drupal | Drupal | 5.0 | 5.0 |
Drupal | Drupal | 6.1 | 6.1 |
Drupal | Drupal | 5.6 | 5.6 |
Drupal | Drupal | 5.1 | 5.1 |
Drupal | Drupal | 6.5 | 6.5 |
Drupal | Drupal | 5.5 | 5.5 |
Drupal | Drupal | 6.0 | 6.0 |
Drupal | Drupal | 5.9 | 5.9 |
Drupal | Drupal | 5.8 | 5.8 |
Drupal | Drupal | 5.3 | 5.3 |
Drupal | Drupal | 6.3 | 6.3 |
Drupal | Drupal | 5.11 | 5.11 |
Drupal5 | Ubuntu | gutsy | * |
Drupal5 | Ubuntu | hardy | * |
Drupal5 | Ubuntu | intrepid | * |
Drupal5 | Ubuntu | upstream | * |
Drupal6 | Ubuntu | upstream | * |