CVE-2007-5593: Code Injection
Published Oct 19, 2007
·Updated
install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified.
Affected Software
2 affected components
Drupal Drupal>=5.0<5.3
fedoraproject fedora=7
Remediation
Patch Available
Event History
Oct 19, 2007
CVE Published
11:17 PM
Oct 20, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5593?
CVE-2007-5593 is classified as a critical vulnerability due to its potential for arbitrary code execution.
2
How does CVE-2007-5593 allow remote code execution?
CVE-2007-5593 allows remote code execution by manipulating the settings.php file when the database server is unreachable.
3
Which versions of Drupal are affected by CVE-2007-5593?
CVE-2007-5593 affects Drupal versions 5.0 to 5.2 before the patch in 5.3 is applied.
4
What is the recommendation to protect against CVE-2007-5593?
It is recommended to upgrade to Drupal 5.3 or later to mitigate the risks associated with CVE-2007-5593.
5
Which operating systems are impacted by CVE-2007-5593?
CVE-2007-5593 specifically affects Drupal 5.x but can also be a concern on systems like Fedora 7 that integrate with it.