Description
SQL injection vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
References (3)
Core 3
Core References
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/05/03/2
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/05/03/1
Vendor Advisory x_refsource_misc
http://drupal.org/node/1557868
Scores
EPSS
0.0041
EPSS Percentile
61.7%
Details
CWE
CWE-89
Status
published
Products (1)
drupal/drupal
Published
Jul 25, 2012
Tracked Since
Feb 18, 2026