First published: Fri Oct 19 2007(Updated: )
install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal | >=5.0<5.3 | |
Fedora | =7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5593 is classified as a critical vulnerability due to its potential for arbitrary code execution.
CVE-2007-5593 allows remote code execution by manipulating the settings.php file when the database server is unreachable.
CVE-2007-5593 affects Drupal versions 5.0 to 5.2 before the patch in 5.3 is applied.
It is recommended to upgrade to Drupal 5.3 or later to mitigate the risks associated with CVE-2007-5593.
CVE-2007-5593 specifically affects Drupal 5.x but can also be a concern on systems like Fedora 7 that integrate with it.