Vulnerable Systems:
* Drupal versions before 4.6.7 and also Drupal 4.7.0.
Certain alas, typical configurations of Apache allows execution of
carefully named arbitrary scripts in the files directory. Drupal now will
attempt to automatically create a .htaccess file in your "files" directory
to protect you. This line references SA_2006_006 to lead Apache administrators to this announcement.
Vendor Status:
Drupal as issued an update for this vulnerablity.