Vulnerability Name:

CVE-2007-4064 (CCN-35637)

Assigned:2007-07-26
Published:2007-07-26
Updated:2017-07-29
Summary:Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Authentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
3.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:N)
3.1 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Athentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
Vulnerability Type:CWE-79
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2007-4064

Source: CONFIRM
Type: UNKNOWN
http://drupal.org/files/sa-2007-018/advisory.txt

Source: CCN
Type: DRUPAL-SA-2007-018
Drupal core - Multiple cross site scripting vulnerabilities

Source: CCN
Type: SA26224
Drupal Multiple Cross-Site Scripting and Request Forgery Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
26224

Source: BID
Type: UNKNOWN
25097

Source: CCN
Type: BID-25097
Drupal Multiple Cross-Site Scripting Vulnerabilities

Source: VUPEN
Type: UNKNOWN
ADV-2007-2697

Source: XF
Type: UNKNOWN
drupal-contenttype-xss(35637)

Source: XF
Type: UNKNOWN
drupal-contenttype-xss(35637)

Source: XF
Type: UNKNOWN
drupal-servervariable-xss(35638)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:drupal:drupal:4.7:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.7.2:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.7.3:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.7.4:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.7.5:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.7.6:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.7_rev1.15:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:5.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Vulnerability Name:

    CVE-2007-4064 (CCN-35638)

    Assigned:2007-07-26
    Published:2007-07-26
    Updated:2007-07-26
    Summary:Drupal is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by multiple unspecified server variables. A remote attacker could exploit this vulnerability in a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
    CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
    Exploitability Metrics:Attack Vector (AV): Network
    Attack Complexity (AC): High
    Privileges Required (PR): None
    User Interaction (UI): None
    Scope:Scope (S): Unchanged
    Impact Metrics:Confidentiality (C): Low
    Integrity (I): None
    Availibility (A): None
    CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
    3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
    Exploitability Metrics:Access Vector (AV): 
    Access Complexity (AC): 
    Authentication (Au): 
    Impact Metrics:Confidentiality (C): 
    Integrity (I): 
    Availibility (A): 
    2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N)
    2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
    Exploitability Metrics:Access Vector (AV): 
    Access Complexity (AC): 
    Athentication (Au): 
    Impact Metrics:Confidentiality (C): 
    Integrity (I): 
    Availibility (A): 
    Vulnerability Consequences:Gain Access
    References:Source: MITRE
    Type: CNA
    CVE-2007-4064

    Source: CCN
    Type: DRUPAL-SA-2007-018
    Drupal core - Multiple cross site scripting vulnerabilities

    Source: CCN
    Type: SA26224
    Drupal Multiple Cross-Site Scripting and Request Forgery Vulnerabilities

    Source: CCN
    Type: BID-25097
    Drupal Multiple Cross-Site Scripting Vulnerabilities

    Source: XF
    Type: UNKNOWN
    drupal-servervariable-xss(35638)

    BACK
    drupal drupal 4.7
    drupal drupal 4.7.0
    drupal drupal 4.7.1
    drupal drupal 4.7.2
    drupal drupal 4.7.3
    drupal drupal 4.7.4
    drupal drupal 4.7.5
    drupal drupal 4.7.6
    drupal drupal 4.7_rev1.15
    drupal drupal 5.0
    drupal drupal 5.1