First published: Fri Dec 11 2009(Updated: )
SQL injection vulnerability in the Taxonomy Timer module 5.x-1.8 and earlier and 6.x-alpha1 and earlier for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Brian Miller Taxonomy Timer | <=5.x-1.8 | |
Brian Miller Taxonomy Timer | <=6.x-1.0-alpha1 | |
Brian Miller Taxonomy Timer | =5.x-0.1 | |
Brian Miller Taxonomy Timer | =5.x-1.0 | |
Brian Miller Taxonomy Timer | =5.x-1.0beta1 | |
Brian Miller Taxonomy Timer | =5.x-1.1 | |
Brian Miller Taxonomy Timer | =5.x-1.2 | |
Brian Miller Taxonomy Timer | =5.x-1.3 | |
Brian Miller Taxonomy Timer | =5.x-1.4 | |
Brian Miller Taxonomy Timer | =5.x-1.6 | |
Brian Miller Taxonomy Timer | =5.x-1.7 | |
Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4296 is considered a high severity SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
To fix CVE-2009-4296, update the Taxonomy Timer module to version 5.x-1.9 or later for Drupal 5 and 6.x-1.1 or later for Drupal 6.
CVE-2009-4296 affects Taxonomy Timer versions 5.x-1.8 and earlier as well as 6.x-alpha1 and earlier.
Yes, if you upgrade to a version that is not affected, such as 5.x-1.9 or 6.x-1.1, you can safely use the Taxonomy Timer module.
CVE-2009-4296 enables attackers to carry out SQL injection attacks, potentially leading to unauthorized access to the database.