First published: Fri Jan 26 2007(Updated: )
SQL injection vulnerability in the Acidfree module for Drupal before 4.6.x-1.0, and before 4.7.x-1.0 in the 4.7 series, allows remote authenticated users with "create acidfree albums" privileges to execute arbitrary SQL commands via node titles.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal | =4.6_1.0 | |
Drupal | =4.7_1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0507 is considered a high severity vulnerability due to its ability to allow remote authenticated users to execute arbitrary SQL commands.
To fix CVE-2007-0507, upgrade to Acidfree 4.6.x-1.0 or 4.7.x-1.0 or later versions.
CVE-2007-0507 affects remote authenticated users of the Acidfree module in Drupal versions before 4.6.x-1.0 and before 4.7.x-1.0.
CVE-2007-0507 allows attackers to perform SQL injection attacks, leading to potential unauthorized database access or modification.
CVE-2007-0507 poses a risk only for users still running affected versions of the Acidfree module in Drupal; those who have updated are not at risk.