First published: Fri Nov 30 2012(Updated: )
SQL injection vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
David Alkire Drag & Drop Gallery | =6.x-1.5 | |
Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4479 is classified as a high severity SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
To fix CVE-2012-4479, upgrade the Drag & Drop Gallery module to version 6.x-1.6 or later.
CVE-2012-4479 affects users of the Drag & Drop Gallery module version 6.x-1.5 on Drupal.
Attackers can execute arbitrary SQL commands, which may lead to data leakage or modification.
While using an updated version of Drupal may mitigate other vulnerabilities, you must ensure that the Drag & Drop Gallery module is also updated to avoid CVE-2012-4479.