CVE-2007-4064: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHPSELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4064?
CVE-2007-4064 is classified as a moderate severity vulnerability affecting multiple versions of Drupal.
How do I fix CVE-2007-4064?
To fix CVE-2007-4064, upgrade your Drupal installation to version 5.2 or later, or 4.7.7 or later.
Who can exploit CVE-2007-4064?
CVE-2007-4064 can be exploited by remote attackers, particularly those with authenticated administrator access.
What types of vulnerabilities does CVE-2007-4064 include?
CVE-2007-4064 includes multiple cross-site scripting (XSS) vulnerabilities that allow arbitrary web script or HTML injection.
Which Drupal versions are affected by CVE-2007-4064?
CVE-2007-4064 affects Drupal versions 4.7.x before 4.7.7 and 5.x before 5.2.