---
title: "CVE-2007-0626\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2007-0626?format=md
keywords: index, follow
---

# CVE-2007-0626

Publication date 31 January 2007

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The comment\_form\_add\_preview function in comment.module in Drupal before
4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post
comments" privileges and access to multiple input filters to execute
arbitrary code by previewing comments, which are not processed by "normal
form validation routines."

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| drupal | 9.10 karmic | Not in release |
| 9.04 jaunty | Not in release |
| 8.10 intrepid | Not in release |
| 8.04 LTS hardy | Not in release |
| 7.10 gutsy | Not in release |
| 7.04 feisty | Fixed 5.1-0ubuntu2.1 |
| 6.10 edgy | Ignored end of life, was needed |
| 6.06 LTS dapper | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0626)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2007-0626)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2007-0626)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2007-0626)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2007-0626>
