Drupal Permissions Privileges and Access Controls Vulnerability - CVE-2008-4789
The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and quotattach files to contentquot related to a quotlogic error.quot