CVE-2006-7109

Drupal Imce Module < 1.5 - Unrestricted File Upload

Title source: rule

Description

Unrestricted file upload vulnerability in IMCE before 1.6, a Drupal module, allows remote authenticated users to upload arbitrary PHP code via a filename with a double extension such as .php.gif.

Scores

EPSS 0.0061
EPSS Percentile 69.3%

Classification

Status draft

Affected Products (1)

drupal/imce_module < 1.5

Timeline

Published Mar 05, 2007
Tracked Since Feb 18, 2026