edna.edu.au

John's web design and music blog

 
Friday Sep 19, 2008

Drupal third-party module vulnerability - Mailsave, Link To Us

Mailsave is a module that is designed to interact with mailhandler. It will detach files that are emailed to the site and save them with the node.

The module trusts the mimetype that is send with the file enabling malicious users with the ability to upload files to execute cross site scripting attacks.

[Read More]

Loading...