CVE-2008-2999

Multiple SQL injection vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
VendorProductVersion
drupalaggregation_module
3.0
drupalaggregation_module
3.1
drupalaggregation_module
3.2
drupalaggregation_module
4.0
drupalaggregation_module
4.1
drupalaggregation_module
4.2
drupalaggregation_module
4.3
drupaldrupal
5.0
drupaldrupal
5.1
drupaldrupal
5.1_rev1.1:_rev1.1
drupaldrupal
5.2
drupaldrupal
5.3
drupaldrupal
5.4
drupaldrupal
5.5.
drupaldrupal
5.7
𝑥
= Vulnerable software versions