CVE-2007-0626
The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing…
Does this matter?
Lower severity and a low EPSS score (3.38%). Track it; it rarely justifies an emergency change on its own.
Description
The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines."
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 3.38% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- drupal/drupal
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2007-01/0670.htmlBroken Link
- http://drupal.org/node/113935Patch, Vendor Advisory
- http://osvdb.org/32136Broken Link
- http://secunia.com/advisories/23960Third Party Advisory
- http://secunia.com/advisories/23990Third Party Advisory
- http://www.securityfocus.com/bid/22306Third Party Advisory, VDB Entry
- http://www.vbdrupal.org/forum/showthread.php?t=786Broken Link
- http://www.vupen.com/english/advisories/2007/0406Third Party Advisory
- http://www.vupen.com/english/advisories/2007/0415Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31940Third Party Advisory, VDB Entry
- http://archives.neohapsis.com/archives/bugtraq/2007-01/0670.htmlBroken Link
- http://drupal.org/node/113935Patch, Vendor Advisory
- http://osvdb.org/32136Broken Link
- http://secunia.com/advisories/23960Third Party Advisory
- http://secunia.com/advisories/23990Third Party Advisory
- http://www.securityfocus.com/bid/22306Third Party Advisory, VDB Entry
- http://www.vbdrupal.org/forum/showthread.php?t=786Broken Link
- http://www.vupen.com/english/advisories/2007/0406Third Party Advisory
- http://www.vupen.com/english/advisories/2007/0415Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31940Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.