install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified.
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00328.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/37265
http://www.securityfocus.com/bid/26119
http://secunia.com/advisories/27352