CVE-2012-4472: David Alkire Drag & Drop Gallery

Medium severity, CVSS 5.1. EPSS: 1.4% chance of exploitation in the next 30 days.

Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the directory specified by the filedir parameter.

Affected products

  • David Alkire Drag & Drop Gallery: up to and including 6.x-1.5

Published 2012-11-30. Last modified 2026-06-16.