Drupal Fixes Highly Critical SQL Injection Flaw
15 Oct
2014
15 Oct
'14
10:04 a.m.
'Drupal has patched a critical SQL injection vulnerability in version 7.x of the content management system that can allow arbitrary code execution. The flaw lies in an API that is specifically designed to help prevent against SQL injection attacks. "Drupal 7 includes a database abstraction API to ensure that queries executed against the database are sanitized to prevent SQL injection attacks," the Drupal advisory says. "A vulnerability in this API allows an attacker to send specially crafted requests resulting in arbitrary SQL execution. Depending on the content of the requests this can lead to privilege escalation, arbitrary PHP execution, or other attacks."'
-- source: http://it.slashdot.org/story/14/10/15/2048218
Cheers, Peter
--
Peter Reutemann, Dept. of Computer Science, University of Waikato, NZ
http://www.cms.waikato.ac.nz/~fracpete/ Ph. +64 (7) 858-5174
3558
Age (days ago)
3558
Last active (days ago)
0 comments
1 participants
participants (1)
-
Peter Reutemann