7.5
CVSSv2

CVE-2006-2742

Published: 01/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Drupal 4.6.x prior to 4.6.7 and 4.7.0 allows remote malicious users to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal 4.6.5

drupal drupal 4.6.6

drupal drupal 4.6.3

drupal drupal 4.6.4

drupal drupal 4.6

drupal drupal 4.6.0

drupal drupal 4.7.0

drupal drupal 4.6.1

drupal drupal 4.6.2

Vendor Advisories

The Drupal update in DSA 1125 contained a regression This update corrects this flaw For completeness, the original advisory text below: Several remote vulnerabilities have been discovered in the Drupal web site platform, which may lead to the execution of arbitrary web script The Common Vulnerabilities and Exposures project identifies the follow ...