Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8ffj-gcr2-r5wm

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer Date Tools" privilege to execute arbitrary SQL commands via unspecified vectors.

SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer Date Tools" privilege to execute arbitrary SQL commands via unspecified vectors.

EPSS

Процентиль: 67%
0.00563
Низкий

Дефекты

CWE-89

Связанные уязвимости

nvd
почти 13 лет назад

SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer Date Tools" privilege to execute arbitrary SQL commands via unspecified vectors.

EPSS

Процентиль: 67%
0.00563
Низкий

Дефекты

CWE-89