CVE Vulnerabilities

CVE-2010-3092

Published: Sep 21, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

Affected Software

NameVendorStart VersionEnd Version
DrupalDrupal5.0 (including)5.0 (including)
DrupalDrupal5.0-beta1 (including)5.0-beta1 (including)
DrupalDrupal5.0-beta2 (including)5.0-beta2 (including)
DrupalDrupal5.0-dev (including)5.0-dev (including)
DrupalDrupal5.0-rc1 (including)5.0-rc1 (including)
DrupalDrupal5.0-rc2 (including)5.0-rc2 (including)
DrupalDrupal5.1 (including)5.1 (including)
DrupalDrupal5.2 (including)5.2 (including)
DrupalDrupal5.3 (including)5.3 (including)
DrupalDrupal5.4 (including)5.4 (including)
DrupalDrupal5.5 (including)5.5 (including)
DrupalDrupal5.6 (including)5.6 (including)
DrupalDrupal5.7 (including)5.7 (including)
DrupalDrupal5.8 (including)5.8 (including)
DrupalDrupal5.9 (including)5.9 (including)
DrupalDrupal5.10 (including)5.10 (including)
DrupalDrupal5.11 (including)5.11 (including)
DrupalDrupal5.12 (including)5.12 (including)
DrupalDrupal5.13 (including)5.13 (including)
DrupalDrupal5.14 (including)5.14 (including)
DrupalDrupal5.15 (including)5.15 (including)
DrupalDrupal5.16 (including)5.16 (including)
DrupalDrupal5.17 (including)5.17 (including)
DrupalDrupal5.18 (including)5.18 (including)
DrupalDrupal5.19 (including)5.19 (including)
DrupalDrupal5.20 (including)5.20 (including)
DrupalDrupal5.21 (including)5.21 (including)
DrupalDrupal5.22 (including)5.22 (including)
Drupal5Ubuntuhardy*
Drupal5Ubuntujaunty*
Drupal5Ubuntukarmic*
Drupal5Ubuntuupstream*
Drupal6Ubuntujaunty*
Drupal6Ubuntukarmic*
Drupal6Ubuntuupstream*

References