The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines."
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-01-31T18:00:00

Updated: 2024-08-07T12:26:54.479Z

Reserved: 2007-01-31T00:00:00

Link: CVE-2007-0626

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2007-01-31T18:28:00.000

Modified: 2021-04-19T13:42:09.930

Link: CVE-2007-0626

cve-icon Redhat

No data.