Vulnerability Name: | CVE-2006-2742 (CCN-26654) | ||||||||
Assigned: | 2006-05-24 | ||||||||
Published: | 2006-05-24 | ||||||||
Updated: | 2018-10-18 | ||||||||
Summary: | SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc. This vulnerability is addressed in the following product releases: Drupal, Drupal, 4.6.7 Drupal, Drupal, 4.7.1 | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-2742 Source: CCN Type: Drupal Security Advisory DRUPAL-SA-2006-005 SQL injection vulnerability Source: CONFIRM Type: Patch, Vendor Advisory http://drupal.org/node/65357 Source: CCN Type: Drupal Web site Drupal Source: CCN Type: SA20140 Drupal SQL Injection and Arbitrary File Execution Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 20140 Source: SECUNIA Type: UNKNOWN 21244 Source: DEBIAN Type: UNKNOWN DSA-1125 Source: DEBIAN Type: DSA-1125 drupal -- several vulnerabilities Source: CCN Type: OSVDB ID: 25908 Drupal database.mysql.inc Multiple Parameter SQL Injection Source: CCN Type: OSVDB ID: 27592 Drupal database.pgsql.inc Multiple Parameter SQL Injection Source: CCN Type: OSVDB ID: 27593 Drupal database.mysqli.inc Multiple Parameter SQL Injection Source: BUGTRAQ Type: UNKNOWN 20060602 [DRUPAL-SA-2006-005] Drupal 4.6.7 / 4.7.1 fixes SQL injection issue Source: BID Type: UNKNOWN 18245 Source: CCN Type: BID-18245 Drupal Multiple Input Validation Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2006-1975 Source: XF Type: UNKNOWN drupal-database-sql-injection(26654) Source: XF Type: UNKNOWN drupal-database-sql-injection(26654) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |