CVE-2011-2715: SQL Injection
Published Jan 14, 2020
·Updated
An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.
Affected Software
3 affected components
composer/drupal/core=6.20
Drupal Drupal=6.20
Drupal Data=6.x-1.0-alpha14
Remediation
Patch Available
Event History
Jan 14, 2020
CVE Published
via MITRE·09:22 PM
Data Sourced
via MITRE·09:22 PM
DescriptionWeakness
Apr 22, 2022
Advisory Published
via GitHub·12:24 AM
Frequently Asked Questions
1
What is the vulnerability ID for this SQL Injection vulnerability in Drupal 6.20 with Data 6.x-1.0-alpha14?
The vulnerability ID for this SQL Injection vulnerability is CVE-2011-2715.
2
What is the severity of CVE-2011-2715?
The severity of CVE-2011-2715 is critical (9.8).
3
How does this SQL Injection vulnerability in Drupal 6.20 with Data 6.x-1.0-alpha14 occur?
This SQL Injection vulnerability occurs due to insufficient sanitization of table names or column names.
4
What is the affected software for CVE-2011-2715?
The affected software for CVE-2011-2715 is Drupal 6.20 with Data 6.x-1.0-alpha14.
5
How can I fix CVE-2011-2715?
To fix CVE-2011-2715, it is recommended to upgrade to a version of Drupal that includes the necessary security patches.