CVE-2007-0505: High severity Drupal Project vulnerability
Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 through 5.x before 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0505?
CVE-2007-0505 is classified as a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2007-0505?
To fix CVE-2007-0505, upgrade to a patched version of the Drupal Project Issue Tracking module released after January 23, 2007.
Who is affected by CVE-2007-0505?
CVE-2007-0505 affects remote authenticated users of the Drupal Project Issue Tracking module versions 4.7.0 through 5.x before 20070123.
What can attackers do with CVE-2007-0505?
Attackers can exploit CVE-2007-0505 to upload and execute arbitrary code on the server by attaching files with executable or multiple file extensions.
Is CVE-2007-0505 an old vulnerability?
Yes, CVE-2007-0505 was reported in 2007, but it is important for sites still using vulnerable versions of the software to address it.