Lucene search

K
cve[email protected]CVE-2007-0658
HistoryFeb 01, 2007 - 10:28 p.m.

CVE-2007-0658

2007-02-0122:28:00
web.nvd.nist.gov
36
drupal
textimage
captcha
remote code execution
cve-2007-0658
security vulnerability

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.8 Medium

AI Score

Confidence

Low

0.095 Low

EPSS

Percentile

94.8%

The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION.

Affected configurations

NVD
Node
drupaldrupalMatch4.7
OR
drupaldrupalMatch4.7.1
OR
drupaldrupalMatch4.7.2
OR
drupaldrupalMatch4.7.3
OR
drupaldrupalMatch4.7.4
OR
drupaldrupalMatch4.7.5
OR
drupaldrupalMatch4.7.6
OR
drupaldrupalMatch4.7_rev1.15
OR
drupaldrupalMatch5.0
OR
drupaldrupalMatch5.1
OR
drupaltextimageMatch4.7
OR
drupaltextimageMatch5.0

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.8 Medium

AI Score

Confidence

Low

0.095 Low

EPSS

Percentile

94.8%