← Back

Imce Module

imce_module

Vendor: Drupal • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Drupal
1Imce Module
Apr 23, 2026
Mar 5, 2007
N/A· v4
N/A· v3
5.5 MEDIUM· v2
Directory traversal vulnerability in the delete function in IMCE before 1.6, a Drupal module, allows remote authenticated users to delete arbitrary files via ".." sequences.
1Drupal
1Imce Module
Apr 23, 2026
Mar 5, 2007
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Unrestricted file upload vulnerability in IMCE before 1.6, a Drupal module, allows remote authenticated users to upload arbitrary PHP code via a filename with a double extension such as .php.gif.