CVE-2006-2742: SQL Injection
Published Jun 1, 2006
·Updated
SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.
Affected Software
9 affected components
Drupal Drupal=4.6.0
Drupal Drupal=4.6
Drupal Drupal=4.6.5
Drupal Drupal=4.6.2
Drupal Drupal=4.6.3
Drupal Drupal=4.6.4
Drupal Drupal=4.7.0
Drupal Drupal=4.6.1
Drupal Drupal=4.6.6
Remediation
Patch Available
Patch Available
Event History
Jun 1, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2742?
CVE-2006-2742 is considered a critical vulnerability due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2006-2742?
To fix CVE-2006-2742, upgrade your Drupal installation to version 4.6.7 or 4.7.0 or later.
3
Which versions of Drupal are affected by CVE-2006-2742?
CVE-2006-2742 affects Drupal versions 4.6.x before 4.6.7 and 4.7.0.
4
What types of attacks exploit CVE-2006-2742?
CVE-2006-2742 can be exploited to execute arbitrary SQL commands via malicious input.
5
What are the consequences of exploiting CVE-2006-2742?
Exploiting CVE-2006-2742 can lead to unauthorized data access, data manipulation, or complete compromise of the database.