6
CVSSv2

CVE-2008-5998

Published: 28/01/2009 Updated: 11/10/2018
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the ajax_checklist_save function in the Ajax Checklist module 5.x prior to 5.x-1.1 for Drupal allow remote authenticated users, with "update ajax checklists" permissions, to execute arbitrary SQL commands via a save operation, related to the (1) nid, (2) qid, and (3) state parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

drupal ajax_checklist 5.x-1.0

Exploits

source: wwwsecurityfocuscom/bid/31384/info The Ajax Checklist module for Drupal is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in SQL queries Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit la ...