John's web design and music blog
Drupal third-party module vulnerability - Mailsave, Link To Us
Mailsave is a module that is designed to
interact with mailhandler. It will detach files that are emailed to
the site and save them with the node.
The module trusts the mimetype that is send with the file
enabling malicious users with the ability to upload files to execute
cross site scripting attacks.
Tags:
blogs
auscert
drupal. internet security
Posted at 12:00AM Sep 19, 2008
by John Chen |


About Me