CVE-2007-4064

NameCVE-2007-4064
DescriptionMultiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
drupalsourcesarge(not affected)
drupalsource(unstable)4.7.7-1low
drupal5source(unstable)5.2-1low

Notes

[sarge] - drupal <not-affected> (Only Drupal 5.x is affected)

Search for package or bug name: Reporting problems