Boletines de Vulnerabilidades |
SA-CORE-2014-005 - Drupal core - SQL injection |
|
| Software afectado | Drupal |
|
Advisory ID: DRUPAL-SA-CORE-2014-005Project: Drupal core Version: 7.xDate: 2014-Oct-15Security risk: 25/25 ( Highly Critical) AC:None/A:None/CI:All/II:All/E:Exploit/TD:AllVulnerability: SQL InjectionDescriptionDrupal 7 includes a database abstraction API to ensure that queries executed against the database are sanitized to prevent SQL injection attacks.A vulnerability in this API allows an attacker to send specially crafted requests resulting in arbitrary SQL execution. Depending on the content More info: https://www.drupal.org/SA-CORE-2014-005 |
|














