Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Avatar_uploader | Avatar_uploader_project | * | 6.x-1.2 (including) |