Drupal security advisory – Previews on comments were not passed through normal form validation routines, enabling users with the ‘post comments’ permission and access to more than one input filter to execute arbitrary code. Affected include Drupal 4.7.x versions before Drupal 4.7.6 and Drupal 5.x versions before Drupal 5.1.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/54105/DRUPAL-SA-2007-005.txt
Source: https://packetstormsecurity.com/files/54105/DRUPAL-SA-2007-005.txt.html

