First published: Mon Aug 14 2006(Updated: )
SQL injection vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Bibliography Module | <=4.7_rev1.13.2.4 | |
Drupal Bibliography Module | <=4.5 | |
Drupal Bibliography Module | <=4.6_rev1.1.1.1.4.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4108 is considered a critical vulnerability due to the potential for remote database manipulation.
To fix CVE-2006-4108, upgrade to the appropriate version of the Drupal Bibliography module, specifically 4.6 after revision 1.1.1.1.4.11 or 4.7 after revision 1.13.2.5.
CVE-2006-4108 allows attackers to execute arbitrary SQL commands, potentially leading to data breaches or site compromise.
CVE-2006-4108 affects Drupal Bibliography module versions 4.5, 4.6 up to revision 1.1.1.1.4.10, and 4.7 up to revision 1.13.2.4.
Any organization using vulnerable versions of the Drupal Bibliography module is at risk of being exploited through CVE-2006-4108.