Drupal Arbitrary File Uploads via BlogAPI Vulnerability
22 Apr. 2012
Summary
The BlogAPI module does not validate the extension of uploaded files, enabling users with the "administer content with blog api" permission to upload harmful files.
Credit:
The information has been provided by Mark Burdett..
The BlogAPI module does not validate the extension of uploaded files, enabling users with the "administer content with blog api" permission to upload harmful files.
Vendor Status:
Drupal issued an update for this vulnerability