PT-2007-2082 · Drupal · Drupal

Publicado

2007-01-31

·

Atualizado

2021-04-19

·

CVE-2007-0626

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Drupal versions prior to 4.7.6 Drupal versions 5.x prior to 5.1
Description The issue allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments. This is possible because the comments are not processed by normal form validation routines when the comment form add preview function is used.
Recommendations For versions prior to 4.7.6, update to version 4.7.6 or later. For versions 5.x prior to 5.1, update to version 5.1 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0626

Produtos afetados

Drupal