8.5

CVE-2007-0505

Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 through 5.x before 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DrupalProject Version4.6
DrupalProject Version4.6_1.1
DrupalProject Version4.7
DrupalProject Version4.7_1.1
DrupalProject Version4.7_2.1
DrupalProject Version5.0 Editiondev
DrupalProject Issue Tracking Module Version5.0 Editiondev
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.63% 0.852
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.5 6.8 10
AV:N/AC:M/Au:S/C:C/I:C/A:C