Title : getID3 Library for Drupal Demonstration Scripts Remote Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-0635 CVE ID : CVE-2007-1035
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-02-16
Technical Description
A vulnerability has been identified in getID3 library (included with Audio and Mediafield modules for Drupal), which could be exploited by remote attackers to execute arbitrary commands. This issue is due to unspecified input validation errors in various demonstration scripts, which could be exploited by attackers to disclose or delete arbitrary files, or write arbitrary data to empty or MP3 files.