VYPR
Unrated severityNVD Advisory· Published Jan 26, 2007· Updated Apr 23, 2026

CVE-2007-0505

CVE-2007-0505

Description

Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 through 5.x before 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.

Affected products

10
  • Drupal/Project6 versions
    cpe:2.3:a:drupal:project:4.6:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:drupal:project:4.6:*:*:*:*:*:*:*
    • cpe:2.3:a:drupal:project:4.6_1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:drupal:project:4.7:*:*:*:*:*:*:*
    • cpe:2.3:a:drupal:project:4.7_1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:drupal:project:4.7_2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:drupal:project:5.0:*:dev:*:*:*:*:*
  • cpe:2.3:a:drupal:project_issue_tracking_module:4.7:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:drupal:project_issue_tracking_module:4.7:*:*:*:*:*:*:*
    • cpe:2.3:a:drupal:project_issue_tracking_module:4.7_1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:drupal:project_issue_tracking_module:4.7_2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:drupal:project_issue_tracking_module:5.0:*:dev:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.