CVE-2005-2106: Medium severity Drupal Drupal vulnerability
Published Jul 1, 2005
·Updated
Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.
Affected Software
6 affected components
Drupal Drupal=4.6.0
Drupal Drupal=4.5.0
Drupal Drupal=4.5.2
Drupal Drupal=4.5.1
Drupal Drupal=4.6.1
Drupal Drupal=4.5.3
Remediation
Patch Available
Event History
Jul 1, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2106?
CVE-2005-2106 is considered to have a high severity due to the potential for remote code execution.
2
How do I fix CVE-2005-2106?
To fix CVE-2005-2106, upgrade to Drupal version 4.6.2 or later to mitigate the vulnerability.
3
Which versions of Drupal are affected by CVE-2005-2106?
CVE-2005-2106 affects Drupal versions 4.5.0 through 4.5.3, as well as 4.6.0 and 4.6.1.
4
What type of attack does CVE-2005-2106 enable?
CVE-2005-2106 enables remote attackers to execute arbitrary PHP code through public comments or postings.
5
Is there a workaround for CVE-2005-2106?
There is no direct workaround for CVE-2005-2106; updating to a secure version is the recommended solution.