
DescriptionSQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
drupal-4.7source(unstable)(not affected)
drupal5source(unstable)(not affected)


- drupal5 <not-affected> (Vulnerable code not present, introduced in 6.0)
- drupal-4.7 <not-affected> (Vulnerable code not present, introduced in 6.0)

Search for package or bug name: Reporting problems