CVE-2007-0626

Publication date 31 January 2007

Last updated 17 July 2025


Ubuntu priority

The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with “post comments” privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by “normal form validation routines.”

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
drupal 9.10 karmic Not in release
9.04 jaunty Not in release
8.10 intrepid Not in release
8.04 LTS hardy Not in release
7.10 gutsy Not in release
7.04 feisty
Fixed 5.1-0ubuntu2.1
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life