First published: Tue Apr 21 2015(Updated: )
SQL injection vulnerability in the PHPlist Integration Module before 6.x-1.7 for Drupal allows remote administrators to execute arbitrary SQL commands via unspecified vectors, related to the "phpList database."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpList | <=6.x-1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3345 has a medium severity rating due to its ability to allow remote administrators to execute arbitrary SQL commands.
To fix CVE-2015-3345, update the PHPlist Integration Module to version 6.x-1.7 or later.
CVE-2015-3345 affects versions up to 6.x-1.6 of the PHPlist Integration Module for Drupal.
CVE-2015-3345 is classified as an SQL injection vulnerability.
CVE-2015-3345 can be exploited by remote administrators with access to the PHPlist Integration Module.