LWN.net Logo

drupal6-views: SQL injection

Package(s):drupal6-views CVE #(s):
Created:November 21, 2011 Updated:November 23, 2011
Description: From the Drupal advisory:

The Views module enables you to list content in your site in various ways. The module doesn't sufficiently escape database parameters for certain filters/arguments on certain types of views with specific configurations of arguments.

Alerts:
Fedora FEDORA-2011-15399 2011-11-04
Fedora FEDORA-2011-15385 2011-11-04
Fedora FEDORA-2011-15352 2011-11-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds