{"api_version":"1","generated_at":"2026-07-23T06:22:31+00:00","cve":"CVE-2007-0626","urls":{"html":"https://cve.report/CVE-2007-0626","api":"https://cve.report/api/cve/CVE-2007-0626.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0626","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0626"},"summary":{"title":"CVE-2007-0626","description":"The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with \"post comments\" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by \"normal form validation routines.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2007-01-31 18:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://osvdb.org/32136","name":"http://osvdb.org/32136","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://drupal.org/node/113935","name":"http://drupal.org/node/113935","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Drupal core - Arbitrary code execution | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2007-01/0670.html","name":"http://archives.neohapsis.com/archives/bugtraq/2007-01/0670.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://secunia.com/advisories/23990","name":"http://secunia.com/advisories/23990","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"vbDrupal Comment Preview Arbitrary Code Execution - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vbdrupal.org/forum/showthread.php?t=786","name":"http://www.vbdrupal.org/forum/showthread.php?t=786","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"vbDrupal 4.7.6.0 released - vbDrupal Forums","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/23960","name":"http://secunia.com/advisories/23960","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Drupal Comment Preview Arbitrary Code Execution - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/0415","name":"http://www.vupen.com/english/advisories/2007/0415","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/22306","name":"http://www.securityfocus.com/bid/22306","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Drupal Comment_Form_Add_Preview Function Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/0406","name":"http://www.vupen.com/english/advisories/2007/0406","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31940","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31940","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0626","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0626","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"626","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"drupal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:26:54.479Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vbdrupal.org/forum/showthread.php?t=786"},{"name":"22306","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/22306"},{"name":"23960","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23960"},{"name":"ADV-2007-0406","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/0406"},{"name":"32136","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/32136"},{"name":"ADV-2007-0415","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/0415"},{"name":"drupal-commentformaddpreview-code-execution(31940)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31940"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/113935"},{"name":"20070129 [DRUPAL-SA-2007-005] Drupal 4.7.6 / 5.1 fixes arbitrary code execution issue","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2007-01/0670.html"},{"name":"23990","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23990"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-01-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with \"post comments\" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by \"normal form validation routines.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.vbdrupal.org/forum/showthread.php?t=786"},{"name":"22306","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/22306"},{"name":"23960","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23960"},{"name":"ADV-2007-0406","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/0406"},{"name":"32136","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/32136"},{"name":"ADV-2007-0415","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/0415"},{"name":"drupal-commentformaddpreview-code-execution(31940)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31940"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/113935"},{"name":"20070129 [DRUPAL-SA-2007-005] Drupal 4.7.6 / 5.1 fixes arbitrary code execution issue","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2007-01/0670.html"},{"name":"23990","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23990"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-0626","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with \"post comments\" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by \"normal form validation routines.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.vbdrupal.org/forum/showthread.php?t=786","refsource":"CONFIRM","url":"http://www.vbdrupal.org/forum/showthread.php?t=786"},{"name":"22306","refsource":"BID","url":"http://www.securityfocus.com/bid/22306"},{"name":"23960","refsource":"SECUNIA","url":"http://secunia.com/advisories/23960"},{"name":"ADV-2007-0406","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/0406"},{"name":"32136","refsource":"OSVDB","url":"http://osvdb.org/32136"},{"name":"ADV-2007-0415","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/0415"},{"name":"drupal-commentformaddpreview-code-execution(31940)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31940"},{"name":"http://drupal.org/node/113935","refsource":"CONFIRM","url":"http://drupal.org/node/113935"},{"name":"20070129 [DRUPAL-SA-2007-005] Drupal 4.7.6 / 5.1 fixes arbitrary code execution issue","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2007-01/0670.html"},{"name":"23990","refsource":"SECUNIA","url":"http://secunia.com/advisories/23990"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-0626","datePublished":"2007-01-31T18:00:00.000Z","dateReserved":"2007-01-31T00:00:00.000Z","dateUpdated":"2024-08-07T12:26:54.479Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-01-31 18:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*","versionStartExcluding":"4.7.0","versionEndExcluding":"4.7.6","matchCriteriaId":"97D83466-2B9B-4C7F-BA2E-1CC2441EA143"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"5.1","matchCriteriaId":"4021FFD0-B361-42FE-91AD-61CF859F4718"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"626","Ordinal":"1","Title":"CVE-2007-0626","CVE":"CVE-2007-0626","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"626","Ordinal":"1","NoteData":"The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with \"post comments\" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by \"normal form validation routines.\"","Type":"Description","Title":"CVE-2007-0626"},{"CveYear":"2007","CveId":"626","Ordinal":"2","NoteData":"2007-01-31","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"626","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}