CVE Vulnerabilities

CVE-2007-5597

Published: Oct 19, 2007 | Modified: Oct 26, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

The hook_comments API in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 does not pass publication status, which might allow attackers to bypass access restrictions and trigger e-mail with unpublished comments from some modules, as demonstrated by (1) Organic groups and (2) Subscriptions.

Affected Software

Name Vendor Start Version End Version
Drupal Drupal 4.7.0 (including) 4.7.8 (excluding)
Drupal Drupal 5.0 (including) 5.3 (excluding)
Drupal5 Ubuntu gutsy *
Drupal5 Ubuntu upstream *

References