Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6299 (Drupal)

BugsAlert Home > CVE-2007-6299 (Drupal)
 
 

Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6299

Learn more about CVE-2007-6299 (Drupal)
 
Tags: cve-2007-6299 drupal

Related Items

      CVE-2008-2225 (gamecms_lite)

      Perl "File::Path::rmtree" Insecure chmod on Symbolic Links

      CVE-2008-3958 (db2)

      rPath update for postfix

      CVE-2008-1445 (windows-nt)

      CVE-2007-6225 (Solaris)

      CVE-2008-2600 (Oracle Database, spatial_component)

 

Pixel