Title : Drupal "comment_form_add_preview()" Comment Preview Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-0406 CVE ID : CVE-2007-0626
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-30
Technical Description
A vulnerability has been identified in Drupal, which could be exploited by remote attackers to execute arbitrary commands. This issue is due to an input validation error in the "comment_form_add_preview()" [comment.module] function when handling user-supplied comments, which could be exploited by remote attackers with "post comments" permissions and access to more than one input filter to compromise a vulnerable web server.