LWN.net Logo

drupal-views: SQL injection

Package(s):drupal-views CVE #(s):
Created:December 22, 2008 Updated:December 24, 2008
Description: From the Drupal security alert:

When using an exposed filter on CCK text fields with allowed values, Views does not filter the data correctly. This may allow malicious users to conduct SQL injection attacks against the site.

Alerts:
Fedora FEDORA-2008-11578 2008-12-21
Fedora FEDORA-2008-11519 2008-12-21

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds