Vulnerability Description
Unspecified vulnerability in certain demonstration scripts in getID3 1.7.1, as used in the Mediafield and Audio modules for Drupal, allows remote attackers to read and delete arbitrary files, list arbitrary directories, and write to empty files or .mp3 files via unknown vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Drupal | Audio Module | All versions |
| Drupal | Getid3 | 1.7.1 |
| Drupal | Mediafield Module | All versions |
References
- http://blamcast.net/articles/highly-critical-security-flaws-in-drupal-audio-modu
- http://drupal.org/node/119385PatchVendor Advisory
- http://osvdb.org/35161
- http://www.securityfocus.com/bid/22587Patch
- http://www.vupen.com/english/advisories/2007/0635
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32542
- http://blamcast.net/articles/highly-critical-security-flaws-in-drupal-audio-modu
- http://drupal.org/node/119385PatchVendor Advisory
- http://osvdb.org/35161
- http://www.securityfocus.com/bid/22587Patch
- http://www.vupen.com/english/advisories/2007/0635
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32542
FAQ
What is CVE-2007-1035?
CVE-2007-1035 is a vulnerability with a CVSS score of 7.5 (HIGH). Unspecified vulnerability in certain demonstration scripts in getID3 1.7.1, as used in the Mediafield and Audio modules for Drupal, allows remote attackers to read and delete arbitrary files, list arb...
How severe is CVE-2007-1035?
CVE-2007-1035 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-1035?
Check the references section above for vendor advisories and patch information. Affected products include: Drupal Audio Module, Drupal Getid3, Drupal Mediafield Module.