CVE-2008-0569
Summary
| CVE | CVE-2008-0569 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-02-05 02:00:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The Comment Upload 4.7.x before 4.7.x-0.1 and 5.x before 5.x-0.1 module for Drupal does not properly use functions in the upload module, which allows remote attackers to bypass upload validation, and upload arbitrary files and possibly execute arbitrary code, via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Drupal | Comment Upload Module | 4.7 | All | All | All |
| Application | Drupal | Comment Upload Module | 5.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SA-2008-015 - Comment Upload - Arbitrary file upload | drupal.org | af854a3a-2127-422b-91ae-364da2661108 | drupal.org | |
| Drupal Comment Upload Module Upload Validation Function Arbitrary File Upload Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| comment_upload 5.x-0.1 | drupal.org | af854a3a-2127-422b-91ae-364da2661108 | drupal.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| comment_upload 4.7.x-0.1 | drupal.org | af854a3a-2127-422b-91ae-364da2661108 | drupal.org | |
| Drupal Comment Upload Module File Upload Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.