First published: Fri Jul 18 2008(Updated: )
SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal | >=6.0<6.3 | |
Fedora | =8 | |
Fedora | =9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3223 is considered a critical severity SQL injection vulnerability that can lead to remote code execution.
To fix CVE-2008-3223, upgrade your Drupal installation to version 6.3 or later which includes the necessary security patch.
CVE-2008-3223 affects all versions of Drupal 6.x prior to 6.3.
Yes, if your web application uses affected versions of Drupal 6.x, it is vulnerable to SQL injection attacks.
CVE-2008-3223 can be exploited to execute arbitrary SQL commands, potentially compromising the entire database.