First published: Mon Dec 10 2007(Updated: )
Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | =4.6.0 | |
Drupal Drupal | =4.6 | |
Drupal Drupal | =4.6.5 | |
Drupal Drupal | =4.5.4 | |
Drupal Drupal | =4.7.2 | |
Drupal Drupal | =4.6.10 | |
Drupal Drupal | =4.6.9 | |
Drupal Drupal | =5.2 | |
Drupal Drupal | =4.5.2 | |
Drupal Drupal | =4.7.5 | |
Drupal Drupal | =4.6.2 | |
Drupal Drupal | =4.6.8 | |
Drupal Drupal | =4.7.3 | |
Drupal Drupal | =5.1_rev1.1 | |
Drupal Drupal | =4.7.8 | |
Drupal Drupal | =4.5.7 | |
Drupal Drupal | =4.4.1 | |
Drupal Drupal | =4.5.1 | |
Drupal Drupal | =5.0 | |
Drupal Drupal | =4.4.2 | |
Drupal Drupal | =4.6.3 | |
Drupal Drupal | =4.5.8 | |
Drupal Drupal | =4.6.4 | |
Drupal Drupal | =4.0.0 | |
Drupal Drupal | =4.6.7 | |
Drupal Drupal | =4.5.5 | |
Drupal Drupal | =4.7_rev1.15 | |
Drupal Drupal | =4.7 | |
Drupal Drupal | =4.7.6 | |
Drupal Drupal | =4.6.11 | |
Drupal Drupal | =4.1.0 | |
Drupal Drupal | =5.1 | |
Drupal Drupal | =4.4.3 | |
Drupal Drupal | =4.7.7 | |
Drupal Drupal | =4.2.0_rc | |
Drupal Drupal | =4.5 | |
Drupal Drupal | =4.6.1 | |
Drupal Drupal | =4.7.4 | |
Drupal Drupal | =4.7.1 | |
Drupal Drupal | =4.5.3 | |
Drupal Drupal | =4.4.0 | |
Drupal Drupal | =4.5.6 | |
Drupal Drupal | =4.6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6299 has a moderate severity rating due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2007-6299, upgrade to Drupal versions 4.7.9 or 5.4, which contain the necessary patches.
CVE-2007-6299 affects Drupal versions 4.7.x before 4.7.9 and 5.x before 5.4.
Yes, CVE-2007-6299 can lead to data breaches by allowing attackers to manipulate the database and access sensitive information.
CVE-2007-6299 has been demonstrated through vulnerabilities in modules such as taxonomy_menu, ajaxLoader, and ubrowser.