CVE-2007-5595
Last modified
CVE-2007-5595 is a vulnerability of currently unknown severity. CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.. EPSS estimates a 1.99% chance of exploitation in the next 30 days.
Description
CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Drupal | Drupal | >= 4.7.0, < 4.7.8 |
| Drupal | Drupal | >= 5.0, < 5.3 |
References
- http://drupal.org/node/184315Vendor Advisory
- http://secunia.com/advisories/27292Third Party Advisory
- http://secunia.com/advisories/27352Third Party Advisory
- http://www.securityfocus.com/bid/26119Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/3546Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37264Third Party Advisory, VDB Entry
- http://drupal.org/node/184315Vendor Advisory
- http://secunia.com/advisories/27292Third Party Advisory
- http://secunia.com/advisories/27352Third Party Advisory
- http://www.securityfocus.com/bid/26119Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/3546Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37264Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5595?
How severe is CVE-2007-5595?
How do I fix CVE-2007-5595?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5589Multiple cross-site scripting (XSS) vulnerabilities in phpMy…
- CVE-2007-5590Multiple buffer overflows in Miranda before 0.7.1 allow remo…
- CVE-2007-5591The CS1000 signaling server in Nortel Enterprise VoIP-Core-C…
- CVE-2007-5592Multiple PHP remote file inclusion vulnerabilities in awzMB …
- CVE-2007-5593install.php in Drupal 5.x before 5.3, when the configured da…
- CVE-2007-5594Drupal 5.x before 5.3 does not apply its Drupal Forms API pr…
- CVE-2007-5596The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x …
- CVE-2007-5597The hook_comments API in Drupal 4.7.x before 4.7.8 and 5.x b…
- CVE-2007-5598Cross-site scripting (XSS) vulnerability in Weblinks for Dru…
- CVE-2007-5599Multiple PHP remote file inclusion vulnerabilities in awrate…
- CVE-2007-5600Incomplete blacklist vulnerability in index.php in Artmedic …
- CVE-2007-5601Stack-based buffer overflow in the Database Component in MPA…
Are you affected by CVE-2007-5595?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
