CVE-2007-6299
Summary
| CVE | CVE-2007-6299 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-12-10 18:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: CWE-20 | CWE-89 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Drupal | Drupal | 4.0.0 | All | All | All |
| Application | Drupal | Drupal | 4.1.0 | All | All | All |
| Application | Drupal | Drupal | 4.2.0_rc | All | All | All |
| Application | Drupal | Drupal | 4.4.0 | All | All | All |
| Application | Drupal | Drupal | 4.4.1 | All | All | All |
| Application | Drupal | Drupal | 4.4.2 | All | All | All |
| Application | Drupal | Drupal | 4.4.3 | All | All | All |
| Application | Drupal | Drupal | 4.5 | All | All | All |
| Application | Drupal | Drupal | 4.5.1 | All | All | All |
| Application | Drupal | Drupal | 4.5.2 | All | All | All |
| Application | Drupal | Drupal | 4.5.3 | All | All | All |
| Application | Drupal | Drupal | 4.5.4 | All | All | All |
| Application | Drupal | Drupal | 4.5.5 | All | All | All |
| Application | Drupal | Drupal | 4.5.6 | All | All | All |
| Application | Drupal | Drupal | 4.5.7 | All | All | All |
| Application | Drupal | Drupal | 4.5.8 | All | All | All |
| Application | Drupal | Drupal | 4.6 | All | All | All |
| Application | Drupal | Drupal | 4.6.0 | All | All | All |
| Application | Drupal | Drupal | 4.6.1 | All | All | All |
| Application | Drupal | Drupal | 4.6.10 | All | All | All |
| Application | Drupal | Drupal | 4.6.11 | All | All | All |
| Application | Drupal | Drupal | 4.6.2 | All | All | All |
| Application | Drupal | Drupal | 4.6.3 | All | All | All |
| Application | Drupal | Drupal | 4.6.4 | All | All | All |
| Application | Drupal | Drupal | 4.6.5 | All | All | All |
| Application | Drupal | Drupal | 4.6.6 | All | All | All |
| Application | Drupal | Drupal | 4.6.7 | All | All | All |
| Application | Drupal | Drupal | 4.6.8 | All | All | All |
| Application | Drupal | Drupal | 4.6.9 | All | All | All |
| Application | Drupal | Drupal | 4.7 | All | All | All |
| Application | Drupal | Drupal | 4.7.1 | All | All | All |
| Application | Drupal | Drupal | 4.7.2 | All | All | All |
| Application | Drupal | Drupal | 4.7.3 | All | All | All |
| Application | Drupal | Drupal | 4.7.4 | All | All | All |
| Application | Drupal | Drupal | 4.7.5 | All | All | All |
| Application | Drupal | Drupal | 4.7.6 | All | All | All |
| Application | Drupal | Drupal | 4.7.7 | All | All | All |
| Application | Drupal | Drupal | 4.7.8 | All | All | All |
| Application | Drupal | Drupal | 4.7_rev1.15 | All | All | All |
| Application | Drupal | Drupal | 5.0 | All | All | All |
| Application | Drupal | Drupal | 5.1 | All | All | All |
| Application | Drupal | Drupal | 5.1_rev1.1 | All | All | All |
| Application | Drupal | Drupal | 5.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Fedora update for drupal - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 8 Update: drupal-5.4-1.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Drupal TAXONOMY_SELECT_NODES() SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| vbDrupal | Free software downloads at SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Patch |
| [SECURITY] Fedora 7 Update: drupal-5.4-1.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Drupal "taxonomy_select_nodes()" SQL Injection - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| vbDrupal "taxonomy_select_nodes()" SQL Injection - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| vbDrupal | Free software downloads at SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Patch |
| SA-2007-031 - Drupal core - SQL Injection possible when certain contributed modules are enabled | drupal.org | af854a3a-2127-422b-91ae-364da2661108 | drupal.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.