CVE-2007-5596: XSS
Published Oct 19, 2007
·Updated
The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files.
Affected Software
2 affected components
Drupal Drupal>=4.7.0<4.7.8
Drupal Drupal>=5.0<5.3
Remediation
Patch Available
Patch Available
Event History
Oct 19, 2007
CVE Published
11:17 PM
Oct 20, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5596?
CVE-2007-5596 is considered a critical vulnerability due to its potential for allowing remote XSS attacks.
2
How do I fix CVE-2007-5596?
To fix CVE-2007-5596, upgrade to Drupal 4.7.8 or later, or 5.3 or later.
3
What types of attacks are possible with CVE-2007-5596?
CVE-2007-5596 allows attackers to conduct cross-site scripting (XSS) attacks via malicious .html files.
4
Which versions of Drupal are affected by CVE-2007-5596?
CVE-2007-5596 affects Drupal versions 4.7.x before 4.7.8 and 5.x before 5.3.
5
What modules are implicated in CVE-2007-5596?
The vulnerability is located in the core Upload module of Drupal.