Описание
SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer Date Tools" privilege to execute arbitrary SQL commands via unspecified vectors.
SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer Date Tools" privilege to execute arbitrary SQL commands via unspecified vectors.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2012-1626
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72356
- http://drupal.org/node/1401026
- http://drupal.org/node/1401434
- http://osvdb.org/78261
- http://secunia.com/advisories/47533
- http://www.openwall.com/lists/oss-security/2012/04/07/1
- http://www.securityfocus.com/bid/51378
Связанные уязвимости
SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer Date Tools" privilege to execute arbitrary SQL commands via unspecified vectors.