CVE-2008-6171
Publication date 19 February 2009
Last updated 24 July 2024
Ubuntu priority
Description
includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| drupal5 | ||
| drupal6 | ||