First published: Wed Jan 31 2007(Updated: )
The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal | >=5.0<5.1 | |
Drupal | >4.7.0<4.7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0626 is considered a critical vulnerability due to its potential for remote code execution.
To fix CVE-2007-0626, upgrade to Drupal version 5.1 or later, or 4.7.6 or later.
CVE-2007-0626 affects users of Drupal versions before 4.7.6 and 5.x before 5.1.
CVE-2007-0626 is a remote code execution vulnerability found in the Drupal comment module.
An attacker must have 'post comments' privileges to exploit CVE-2007-0626.