Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Drupal | — | Upgrade to Drupal version 5.4Upgrade to Drupal version 4.7.9 | Aug 2, 2017 | Dec 10, 2007 |
| Freebsd | — | Upgrade drupal4Upgrade drupal5 | Dec 10, 2025 | Dec 12, 2007 |
| Ubuntu | — | Upgrade drupal5Upgrade drupal | Nov 19, 2024 | Dec 10, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub