CVE-2012-1626
20.09.2012, 03:46
SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer Date Tools" privilege to execute arbitrary SQL commands via unspecified vectors.
Vendor | Product | Version |
---|---|---|
karen_stevenson | date | 6.x-2.0:x |
karen_stevenson | date | 6.x-2.0:x |
karen_stevenson | date | 6.x-2.0:x |
karen_stevenson | date | 6.x-2.0:x |
karen_stevenson | date | 6.x-2.0:x |
karen_stevenson | date | 6.x-2.0:x |
karen_stevenson | date | 6.x-2.0:x |
karen_stevenson | date | 6.x-2.0:x |
karen_stevenson | date | 6.x-2.0:x |
karen_stevenson | date | 6.x-2.0:x |
karen_stevenson | date | 6.x-2.0:x |
karen_stevenson | date | 6.x-2.1:x |
karen_stevenson | date | 6.x-2.2:x |
karen_stevenson | date | 6.x-2.3:x |
karen_stevenson | date | 6.x-2.4:x |
karen_stevenson | date | 6.x-2.5:x |
karen_stevenson | date | 6.x-2.6:x |
karen_stevenson | date | 6.x-2.7:x |
karen_stevenson | date | 6.x-2.x:x |
𝑥
= Vulnerable software versions
References