CVE-2012-5653: Debian Linux

Medium severity, CVSS 6.0. EPSS: 1.7% chance of exploitation in the next 30 days.

The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.

Affected products

  • Debian Debian Linux: version 6.0 only; version 7.0 only
  • Drupal Drupal: version 7.0 only; version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; …

Published 2013-01-03. Last modified 2026-06-16.