CVE Database
/

CVE-2007-5416

Back to search

CVE-2007-5416

Published: Oct 12, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by invoking the drupal_eval function through a callback parameter to the default URI, as demonstrated by the _menu[callbacks][1][callback] parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Drupal.

VendorProductVersions

n/a

n/a

affected
n/a

References

20071010 Vulnerabilities digest
mailing-list
x_refsource_BUGTRAQ
3216
third-party-advisory
x_refsource_SREASON
4510
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now