SQL Injection in Drupal - CVE-2015-6665
Published: September 14, 2016
Vulnerability identifier: #VU428
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-6665
CWE-ID: CWE-564
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows user with elevated permissions to get access to sensitive information.
The weakness exists due to SQL injection. The attacker inject specially crafted code inunsufficiently filtered SQL comments.
Successful exploitation of this vulnerability allows a malicious user to obtain potentially sensitive information.
The weakness exists due to SQL injection. The attacker inject specially crafted code inunsufficiently filtered SQL comments.
Successful exploitation of this vulnerability allows a malicious user to obtain potentially sensitive information.
Affected software
Drupal
Fedora
drupal6
drupal7
Fedora
drupal6
drupal7
How to mitigate CVE-2015-6665
drupal6 - addressed in versions 6.37-1.el5, 6.37-1.el6, 6.37-1.fc21, 6.37-1.fc22, 6.37-1.fc23
drupal7 - addressed in versions 7.39-1.el5, 7.39-1.el6, 7.39-1.el7, 7.39-1.fc21, 7.39-1.fc22, 7.39-1.fc23
drupal7 - addressed in versions 7.39-1.el5, 7.39-1.el6, 7.39-1.el7, 7.39-1.fc21, 7.39-1.fc22, 7.39-1.fc23
External References
Related Security Bulletins
- SQL Injection in Drupal Drupal
- Fedora 23 update for drupal7
- Fedora 22 update for drupal7
- Fedora 21 update for drupal7
- Fedora EPEL 7 update for drupal7
- Fedora EPEL 6 update for drupal7
- Fedora EPEL 5 update for drupal7
- Fedora 21 update for drupal6
- Fedora 23 update for drupal6
- Fedora 22 update for drupal6
- Fedora EPEL 5 update for drupal6
- Fedora EPEL 6 update for drupal6