6
CVSSv2

CVE-2007-0507

Published: 26/01/2007 Updated: 29/07/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the Acidfree module for Drupal prior to 4.6.x-1.0, and prior to 4.7.x-1.0 in the 4.7 series, allows remote authenticated users with "create acidfree albums" privileges to execute arbitrary SQL commands via node titles.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

drupal acidfree 4.6_1.0

drupal acidfree 4.7_1.0