SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-5593

install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified.

MEDIUM 6.8EPSS 3.77%

Does this matter?

Lower severity and a low EPSS score (3.77%). Track it; it rarely justifies an emergency change on its own.

Description

install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
3.77% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
drupal/drupal · fedoraproject/fedora
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.