Vulnerability Name: | CVE-2007-0626 (CCN-31940) | ||||||||
Assigned: | 2007-01-29 | ||||||||
Published: | 2007-01-29 | ||||||||
Updated: | 2021-04-19 | ||||||||
Summary: | The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines." | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P) 4.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: BUGTRAQ Type: Broken Link 20070129 [DRUPAL-SA-2007-005] Drupal 4.7.6 / 5.1 fixes arbitrary code execution issue Source: MITRE Type: CNA CVE-2007-0626 Source: CCN Type: DRUPAL-SA-2007-005 Drupal core - Arbitrary code execution Source: CONFIRM Type: Patch, Vendor Advisory http://drupal.org/node/113935 Source: OSVDB Type: Broken Link 32136 Source: CCN Type: SA23960 Drupal Comment Preview Arbitrary Code Execution Source: SECUNIA Type: Third Party Advisory 23960 Source: CCN Type: SA23990 vbDrupal Comment Preview Arbitrary Code Execution Source: SECUNIA Type: Third Party Advisory 23990 Source: CCN Type: OSVDB ID: 32136 Drupal Comment Module comment_form_add_preview Function Arbitrary Code Execution Source: CCN Type: OSVDB ID: 35848 vbDrupal Multiple Unspecified Remote Issues Source: BID Type: Third Party Advisory, VDB Entry 22306 Source: CCN Type: BID-22306 Drupal Comment_Form_Add_Preview Function Remote Code Execution Vulnerability Source: CONFIRM Type: Broken Link http://www.vbdrupal.org/forum/showthread.php?t=786 Source: VUPEN Type: Third Party Advisory ADV-2007-0406 Source: VUPEN Type: Third Party Advisory ADV-2007-0415 Source: XF Type: Third Party Advisory, VDB Entry drupal-commentformaddpreview-code-execution(31940) Source: XF Type: UNKNOWN drupal-commentformaddpreview-code-execution(31940) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |