CVE Vulnerabilities

CVE-2007-0507

Published: Jan 26, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in the Acidfree module for Drupal before 4.6.x-1.0, and before 4.7.x-1.0 in the 4.7 series, allows remote authenticated users with create acidfree albums privileges to execute arbitrary SQL commands via node titles.

Affected Software

Name Vendor Start Version End Version
Acidfree Drupal 4.6_1.0 (including) 4.6_1.0 (including)
Acidfree Drupal 4.7_1.0 (including) 4.7_1.0 (including)

References