install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified.
References
Link | Resource |
---|---|
http://drupal.org/files/sa-2007-025/SA-2007-025-5.2.patch | Patch Vendor Advisory |
http://drupal.org/node/184316 | Vendor Advisory |
http://secunia.com/advisories/27290 | Third Party Advisory |
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00328.html | Third Party Advisory |
http://www.securityfocus.com/bid/26119 | Third Party Advisory VDB Entry |
http://secunia.com/advisories/27352 | Third Party Advisory |
http://osvdb.org/39648 | Broken Link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/37265 | Third Party Advisory VDB Entry |
Information
Published : 2007-10-19 16:17
Updated : 2021-04-19 13:59
NVD link : CVE-2007-5593
Mitre link : CVE-2007-5593
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
drupal
- drupal
fedoraproject
- fedora