Description
Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 through 5.x before 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.
Affected products
- Drupal / project4.6 – 4.6
- Drupal / project4.6_1.1 – 4.6_1.1
- Drupal / project4.7 – 4.7
- Drupal / project4.7_1.1 – 4.7_1.1
- Drupal / project4.7_2.1 – 4.7_2.1
- Drupal / project5.0 – 5.0
- Drupal / project_issue_tracking_module4.7 – 4.7
- Drupal / project_issue_tracking_module4.7_1.1 – 4.7_1.1
- Drupal / project_issue_tracking_module4.7_2.1 – 4.7_2.1
- Drupal / project_issue_tracking_module5.0 – 5.0