Launchpad.net

CVE 2007-5593

install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified.

See the CVE page on Mitre.org for more details.