Back

CVE-2005-2106

Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.

Published: Jul 5, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
drupal drupal 4.5.0
drupal drupal 4.5.1
drupal drupal 4.5.2
drupal drupal 4.5.3
drupal drupal 4.6.0
drupal drupal 4.6.1

GitHub Security Advisory GHSA-6vg8-8jg2-mmpm

Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 3.20%

Top 13% most likely to be exploited

Threat Score 21 / 100

Data Sources

NVD EPSS GitHub