CVE-2011-4113

Drupal Views <6.x-2.13 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments."

References (9)

Core 9
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/11/04/3
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/71124
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/50500
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069499.html
Patch x_refsource_misc
http://drupal.org/node/1329898
Patch x_refsource_confirm
http://drupal.org/node/1329842
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/76809
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46680
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46962

Scores

EPSS 0.0171
EPSS Percentile 74.9%

Details

CWE
CWE-89
Status published
Products (27)
earl_miles/views 4.7.x-1.0
earl_miles/views 4.7.x-1.1
earl_miles/views 4.7.x-1.2
earl_miles/views 4.7.x-1.3
earl_miles/views 4.7.x-1.4
earl_miles/views 4.7.x-1.4.2
earl_miles/views 4.7.x-1.6 (5 CPE variants)
earl_miles/views 4.7.x-1.x dev
earl_miles/views 4.7.x1.5
earl_miles/views 5.x-1.0
... and 17 more
Published Feb 17, 2012
Tracked Since Feb 18, 2026