CVE-2006-2743

Drupal 4.6.x < 4.6.7 and 4.7.0 - Arbitrary File Upload and Execution via Multiple File Extensions

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-2743. PoCs published by rgod.

AI-analyzed exploit summary This exploit targets a file upload vulnerability in Drupal <= 4.7, allowing authenticated users to upload malicious files with double extensions (e.g., .php.jpg) to bypass restrictions and achieve remote code execution (RCE). The PoC demonstrates uploading a PHP shell and executing arbitrary commands via HTTP requests.

Description

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1821

This exploit targets a file upload vulnerability in Drupal <= 4.7, allowing authenticated users to upload malicious files with double extensions (e.g., .php.jpg) to bypass restrictions and achieve remote code execution (RCE). The PoC demonstrates uploading a PHP shell and executing arbitrary commands via HTTP requests.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Drupal <= 4.7
Auth required
Prerequisites: Valid Drupal user credentials with upload rights · Access to the Drupal upload functionality
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Patch, Vendor Advisory x_refsource_confirm
http://drupal.org/node/65409
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20140
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26655
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/435794/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18245
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1975
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1125
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/1821
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21244

Scores

EPSS 0.1091
EPSS Percentile 95.3%

Details

Status published
Products (9)
drupal/drupal 4.6
drupal/drupal 4.6.0
drupal/drupal 4.6.1
drupal/drupal 4.6.2
drupal/drupal 4.6.3
drupal/drupal 4.6.4
drupal/drupal 4.6.5
drupal/drupal 4.6.6
drupal/drupal 4.7.0
Published Jun 01, 2006
Tracked Since Feb 18, 2026