vbDrupal Comment Preview Arbitrary Code Execution

Posted on Tuesday, January 30, 2007 @ 17:22:45 CST in Security
by Raven

SECUNIA ADVISORY ID: SA23990

VERIFY ADVISORY: http://secunia.com/advisories/23990/

CRITICAL: Highly critical

IMPACT: System access

SOFTWARE: vbDrupal 4.x - http://secunia.com/product/13380/

DESCRIPTION: A vulnerability has been reported in vbDrupal, which can be exploited by malicious people to compromise a vulnerable system.
For more information: SA23960. Note: This also fixes two other unspecified security issues.

SOLUTION: Update to version 4.7.6.

ORIGINAL ADVISORY: http://www.vbdrupal.org/forum/showthread.php?t=786

OTHER REFERENCES: SA23960: http://secunia.com/advisories/23960/