CVE-2007-0626
Publication date 31 January 2007
Last updated 17 July 2025
Ubuntu priority
The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with “post comments” privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by “normal form validation routines.”
Status
Package | Ubuntu Release | Status |
---|---|---|
drupal | 9.10 karmic | Not in release |
9.04 jaunty | Not in release | |
8.10 intrepid | Not in release | |
8.04 LTS hardy | Not in release | |
7.10 gutsy | Not in release | |
7.04 feisty |
Fixed 5.1-0ubuntu2.1
|
|
6.10 edgy | Ignored end of life, was needed | |
6.06 LTS dapper | Ignored end of life |