CVE-2015-3345: SQL Injection
Published Apr 21, 2015
·Updated
SQL injection vulnerability in the PHPlist Integration Module before 6.x-1.7 for Drupal allows remote administrators to execute arbitrary SQL commands via unspecified vectors, related to the "phpList database."
Affected Software
1 affected component
Phplist Integration Project Phplist Integration Drupal<=6.x-1.6
Remediation
Patch Available
Patch Available
Event History
Apr 21, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3345?
CVE-2015-3345 has a medium severity rating due to its ability to allow remote administrators to execute arbitrary SQL commands.
2
How do I fix CVE-2015-3345?
To fix CVE-2015-3345, update the PHPlist Integration Module to version 6.x-1.7 or later.
3
What software is affected by CVE-2015-3345?
CVE-2015-3345 affects versions up to 6.x-1.6 of the PHPlist Integration Module for Drupal.
4
What type of vulnerability is CVE-2015-3345?
CVE-2015-3345 is classified as an SQL injection vulnerability.
5
Who can exploit CVE-2015-3345?
CVE-2015-3345 can be exploited by remote administrators with access to the PHPlist Integration Module.