Vulnerability Bulletins

SA-CORE-2009-003 - Local file inclusion on Windows

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2009-003Project: Drupal coreVersions: 6.xDate: 2009-February-25Security risk: Highly CriticalExploitable from: RemoteVulnerability: Local file inclusion on WindowsDescriptionThis vulnerability exists on Windows, regardless of the type of webserver (Apache, IIS) used.The Drupal theme system takes URL arguments into account when selecting a template file to use for page rendering. While doing so, it doesnt take into account how Windows arrives at a canonicalized path.

More info:

https://www.drupal.org/node/383724