Description
SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments."
References (9)
Core 9
Core References
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/11/04/3
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/71124
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/50500
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069499.html
Patch x_refsource_misc
http://drupal.org/node/1329898
Patch x_refsource_confirm
http://drupal.org/node/1329842
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/76809
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/46680
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/46962
Scores
EPSS
0.0171
EPSS Percentile
74.9%
Details
CWE
CWE-89
Status
published
Products (27)
earl_miles/views
4.7.x-1.0
earl_miles/views
4.7.x-1.1
earl_miles/views
4.7.x-1.2
earl_miles/views
4.7.x-1.3
earl_miles/views
4.7.x-1.4
earl_miles/views
4.7.x-1.4.2
earl_miles/views
4.7.x-1.6 (5 CPE variants)
earl_miles/views
4.7.x-1.x dev
earl_miles/views
4.7.x1.5
earl_miles/views
5.x-1.0
... and 17 more
Published
Feb 17, 2012
Tracked Since
Feb 18, 2026