9.3

CVE-2008-3001

The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed that allows upload of files with arbitrary extensions.

Data is provided by the National Vulnerability Database (NVD)
DrupalAggregation Module Version3.0
DrupalAggregation Module Version3.1
DrupalAggregation Module Version3.2
DrupalAggregation Module Version4.0
DrupalAggregation Module Version4.1
DrupalAggregation Module Version4.2
DrupalAggregation Module Version4.3
DrupalAggregation Module Version5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.2% 0.829
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.