{"api_version":"1","generated_at":"2026-07-23T05:39:27+00:00","cve":"CVE-2007-0136","urls":{"html":"https://cve.report/CVE-2007-0136","api":"https://cve.report/api/cve/CVE-2007-0136.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0136","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0136"},"summary":{"title":"CVE-2007-0136","description":"Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules.  NOTE: some of these details are obtained from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-01-09 11:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/456054/100/100/threaded","name":"http://www.securityfocus.com/archive/1/456054/100/100/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/files/sa-2007-001/advisory.txt","name":"http://drupal.org/files/sa-2007-001/advisory.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/104233","name":"http://drupal.org/node/104233","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Drupal core - Cross site scripting | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31311","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31311","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/32139","name":"http://osvdb.org/32139","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/0050","name":"http://www.vupen.com/english/advisories/2007/0050","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/32140","name":"http://osvdb.org/32140","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://marc.info/?l=full-disclosure&m=116799778408115&w=2","name":"http://marc.info/?l=full-disclosure&m=116799778408115&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"'[Full-disclosure] [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0136","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0136","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"136","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"drupal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:03:37.142Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"drupal-core-unspecified-xss(31311)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31311"},{"name":"32140","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/32140"},{"name":"20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes XSS issue","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/456054/100/100/threaded"},{"name":"32139","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/32139"},{"name":"ADV-2007-0050","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/0050"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/files/sa-2007-001/advisory.txt"},{"name":"20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://marc.info/?l=full-disclosure&m=116799778408115&w=2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/104233"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-01-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules.  NOTE: some of these details are obtained from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"drupal-core-unspecified-xss(31311)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31311"},{"name":"32140","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/32140"},{"name":"20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes XSS issue","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/456054/100/100/threaded"},{"name":"32139","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/32139"},{"name":"ADV-2007-0050","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/0050"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/files/sa-2007-001/advisory.txt"},{"name":"20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://marc.info/?l=full-disclosure&m=116799778408115&w=2"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/104233"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-0136","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules.  NOTE: some of these details are obtained from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"drupal-core-unspecified-xss(31311)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31311"},{"name":"32140","refsource":"OSVDB","url":"http://osvdb.org/32140"},{"name":"20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes XSS issue","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/456054/100/100/threaded"},{"name":"32139","refsource":"OSVDB","url":"http://osvdb.org/32139"},{"name":"ADV-2007-0050","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/0050"},{"name":"http://drupal.org/files/sa-2007-001/advisory.txt","refsource":"CONFIRM","url":"http://drupal.org/files/sa-2007-001/advisory.txt"},{"name":"20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes","refsource":"FULLDISC","url":"http://marc.info/?l=full-disclosure&m=116799778408115&w=2"},{"name":"http://drupal.org/node/104233","refsource":"CONFIRM","url":"http://drupal.org/node/104233"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-0136","datePublished":"2007-01-09T11:00:00.000Z","dateReserved":"2007-01-08T00:00:00.000Z","dateUpdated":"2024-08-07T12:03:37.142Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-01-09 11:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6.0","versionEndExcluding":"4.6.11","matchCriteriaId":"B9635440-09DB-4948-9892-03BA3B288A09"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*","versionStartIncluding":"4.7.0","versionEndExcluding":"4.7.5","matchCriteriaId":"ECFC350B-88E9-4003-B143-2557E7409439"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"136","Ordinal":"1","Title":"CVE-2007-0136","CVE":"CVE-2007-0136","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"136","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules.  NOTE: some of these details are obtained from third party information.","Type":"Description","Title":"CVE-2007-0136"},{"CveYear":"2007","CveId":"136","Ordinal":"2","NoteData":"2007-01-09","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"136","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}