CVE-2007-6299: SQL Injection
Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomyselectnodes function, as demonstrated by the (1) taxonomymenu, (2) ajaxLoader, and (3) ubrowser contributed modules.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6299?
CVE-2007-6299 has a moderate severity rating due to its potential to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2007-6299?
To fix CVE-2007-6299, upgrade to Drupal versions 4.7.9 or 5.4, which contain the necessary patches.
What versions of Drupal are affected by CVE-2007-6299?
CVE-2007-6299 affects Drupal versions 4.7.x before 4.7.9 and 5.x before 5.4.
Can CVE-2007-6299 lead to data breaches?
Yes, CVE-2007-6299 can lead to data breaches by allowing attackers to manipulate the database and access sensitive information.
Are any specific modules associated with CVE-2007-6299?
CVE-2007-6299 has been demonstrated through vulnerabilities in modules such as taxonomy_menu, ajaxLoader, and ubrowser.