FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-6299

This CVE name corresponds to:

Entered Topic
2007-12-12 drupal -- SQL injection vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-6299
Phase Assigned(20071210)

Description

Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules.

References

Source Reference
CONFIRM http://drupal.org/node/198162
CONFIRM http://sourceforge.net/project/shownotes.php?release_id=559532
CONFIRM http://sourceforge.net/project/shownotes.php?release_id=559538
FEDORA FEDORA-2007-4136
FEDORA FEDORA-2007-4163
BID 26735
SECUNIA 27932
SECUNIA 27951
SECUNIA 27973
XF drupal-taxonomy-sql-injection(38884)
XF vbdrupal-taxonomy-sql-injection(38886)