CVE-2007-0505

Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 through 5.x before 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:drupal:project:4.6:*:*:*:*:*:*:*
cpe:2.3:a:drupal:project:4.6_1.1:*:*:*:*:*:*:*
cpe:2.3:a:drupal:project:4.7:*:*:*:*:*:*:*
cpe:2.3:a:drupal:project:4.7_1.1:*:*:*:*:*:*:*
cpe:2.3:a:drupal:project:4.7_2.1:*:*:*:*:*:*:*
cpe:2.3:a:drupal:project:5.0:*:dev:*:*:*:*:*
cpe:2.3:a:drupal:project_issue_tracking_module:4.7:*:*:*:*:*:*:*
cpe:2.3:a:drupal:project_issue_tracking_module:4.7_1.1:*:*:*:*:*:*:*
cpe:2.3:a:drupal:project_issue_tracking_module:4.7_2.1:*:*:*:*:*:*:*
cpe:2.3:a:drupal:project_issue_tracking_module:5.0:*:dev:*:*:*:*:*

History

21 Nov 2024, 00:26

Type Values Removed Values Added
References () http://drupal.org/node/112146 - Patch, Vendor Advisory () http://drupal.org/node/112146 - Patch, Vendor Advisory
References () http://osvdb.org/32134 - () http://osvdb.org/32134 -
References () http://secunia.com/advisories/23887 - () http://secunia.com/advisories/23887 -
References () http://www.securityfocus.com/bid/22224 - () http://www.securityfocus.com/bid/22224 -
References () http://www.vupen.com/english/advisories/2007/0312 - () http://www.vupen.com/english/advisories/2007/0312 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/31729 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/31729 -

Information

Published : 2007-01-26 00:28

Updated : 2024-11-21 00:26


NVD link : CVE-2007-0505

Mitre link : CVE-2007-0505

CVE.ORG link : CVE-2007-0505


JSON object : View

Products Affected

drupal

  • project
  • project_issue_tracking_module