Drupal IMCE Module Arbitrary File Deletion Vulnerability
BID:20312
Info
Drupal IMCE Module Arbitrary File Deletion Vulnerability
| Bugtraq ID: | 20312 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-7110 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2006 12:00AM |
| Updated: | Jul 06 2016 02:40PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Drupal IMCE for TinyMCE 4.6 |
| Not Vulnerable: |
Drupal IMCE for TinyMCE 4.7 |
Discussion
Drupal IMCE Module Arbitrary File Deletion Vulnerability
The Drupal IMCE module is prone to an arbitrary file-deletion vulnerability because the application fails to sufficiently sanitize user-supplied input.
Successfully exploiting this issue allows attackers to delete arbitrary files with the privileges of the targeted webserver process.
The Drupal IMCE module is prone to an arbitrary file-deletion vulnerability because the application fails to sufficiently sanitize user-supplied input.
Successfully exploiting this issue allows attackers to delete arbitrary files with the privileges of the targeted webserver process.
Exploit / POC
Drupal IMCE Module Arbitrary File Deletion Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
Drupal IMCE Module Arbitrary File Deletion Vulnerability
Solution:
The vendor has released an update to address this issue. Please see the references for more information.
Solution:
The vendor has released an update to address this issue. Please see the references for more information.
References
Drupal IMCE Module Arbitrary File Deletion Vulnerability
References:
References:
- Drupal ICME for TinyMCE Home Page (Drupal)
- Drupal Security Advisory DRUPAL-SA-2006-022 (Drupal)