Vulnerabilities > CVE-2007-0626 - Unspecified vulnerability in Drupal 5.0

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
drupal
nessus

Summary

The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines."

Vulnerable Configurations

Part Description Count
Application
Drupal
6

Nessus

  • NASL familyCGI abuses
    NASL idDRUPAL_COMMENT_CODE_EXEC.NASL
    descriptionThe version of Drupal running on the remote host fails to properly validate previews on comments, and allows access to more than one input filter, which is not enabled by default. An attacker can exploit this issue by previewing a comment to have it interpreted as PHP code, resulting in arbitrary code execution with the privileges of the web server user id.
    last seen2020-06-01
    modified2020-06-02
    plugin id24265
    published2007-02-01
    reporterThis script is Copyright (C) 2007-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/24265
    titleDrupal Comment Function Arbitrary Code Execution
  • NASL familyCGI abuses
    NASL idDRUPAL_COMMENT_CODE_EXEC2.NASL
    descriptionThe version of Drupal running on the remote host fails to properly validate previews on comments, and allows access to more than one input filter, which is not enabled by default. An attacker can exploit this issue by previewing a comment to have it interpreted as PHP code, resulting in arbitrary code execution with the privileges of the web server user id.
    last seen2020-06-01
    modified2020-06-02
    plugin id24266
    published2007-02-01
    reporterThis script is Copyright (C) 2007-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/24266
    titleDrupal Comment Module comment_form_add_preview() Function Arbitrary Code Execution