CVE-2007-0626: Medium severity Drupal Drupal vulnerability
Published Jan 31, 2007
·Updated
The commentformaddpreview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines."
Affected Software
2 affected components
Drupal Drupal>=5.0<5.1
Drupal Drupal>4.7.0<4.7.6
Remediation
Patch Available
Event History
Jan 31, 2007
CVE Published
06:28 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0626?
CVE-2007-0626 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2007-0626?
To fix CVE-2007-0626, upgrade to Drupal version 5.1 or later, or 4.7.6 or later.
3
Who is affected by CVE-2007-0626?
CVE-2007-0626 affects users of Drupal versions before 4.7.6 and 5.x before 5.1.
4
What type of vulnerability is CVE-2007-0626?
CVE-2007-0626 is a remote code execution vulnerability found in the Drupal comment module.
5
Can an attacker exploit CVE-2007-0626 without special permissions?
An attacker must have 'post comments' privileges to exploit CVE-2007-0626.