PT-2007-2082 · Drupal · Drupal

Published

2007-01-31

·

Updated

2021-04-19

·

CVE-2007-0626

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Drupal versions prior to 4.7.6 Drupal versions 5.x prior to 5.1
Description The issue allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments. This is possible because the comments are not processed by normal form validation routines when the comment form add preview function is used.
Recommendations For versions prior to 4.7.6, update to version 4.7.6 or later. For versions 5.x prior to 5.1, update to version 5.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0626

Affected Products

Drupal