SQL injection in Drupal - CVE-2015-6659
Published: August 24, 2015 / Updated: December 5, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Affected software
Fedora
drupal6
drupal7
How to mitigate CVE-2015-6659
drupal6 - addressed in versions 6.37-1.el5, 6.37-1.el6, 6.37-1.fc21, 6.37-1.fc22, 6.37-1.fc23
drupal7 - addressed in versions 7.39-1.el5, 7.39-1.el6, 7.39-1.el7, 7.39-1.fc21, 7.39-1.fc22, 7.39-1.fc23
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165061.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165690.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165704.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165723.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165733.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165840.html
- http://www.debian.org/security/2015/dsa-3346
- http://www.securityfocus.com/bid/76432
- http://www.securitytracker.com/id/1033358
- https://www.drupal.org/SA-CORE-2015-003
Related Security Bulletins
- SQL injection in Drupal
- Fedora 23 update for drupal7
- Fedora 22 update for drupal7
- Fedora 21 update for drupal7
- Fedora EPEL 7 update for drupal7
- Fedora EPEL 6 update for drupal7
- Fedora EPEL 5 update for drupal7
- Fedora 21 update for drupal6
- Fedora 23 update for drupal6
- Fedora 22 update for drupal6
- Fedora EPEL 5 update for drupal6
- Fedora EPEL 6 update for drupal6