PT-2007-1965 · Drupal · Drupal

Published

2007-01-26

·

Updated

2017-07-29

·

CVE-2007-0505

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Drupal Project issue tracking module versions 4.7.0 through 5.x before 20070123
Description The issue allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.
Recommendations For versions 4.7.0 through 5.x before 20070123, consider restricting file uploads to only authorized users and validating file extensions to prevent executable files from being uploaded until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0505

Affected Products

Drupal