CVE-2011-4113: SQL Injection
SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments."
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4113?
CVE-2011-4113 has been classified as a critical vulnerability due to its potential to allow arbitrary SQL command execution.
How do I fix CVE-2011-4113?
To fix CVE-2011-4113, update the Views module to version 6.x-2.13 or later.
Who is affected by CVE-2011-4113?
CVE-2011-4113 affects users of the Views module for Drupal versions prior to 6.x-2.13.
What types of attacks exploit CVE-2011-4113?
Attackers can exploit CVE-2011-4113 through SQL injection attacks targeting specific configurations of views with filters or arguments.
Are there any specifics about vulnerable configurations for CVE-2011-4113?
CVE-2011-4113 is vulnerable when certain types of views with specific configurations of arguments are in use.