Drupal Extended Tracker Unspecified SQL Injection Vulnerability
BID:20759
Info
Drupal Extended Tracker Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 20759 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2006 12:00AM |
| Updated: | Oct 27 2006 06:28PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Drupal Extended Tracker 4.7 |
| Not Vulnerable: | |
Discussion
Drupal Extended Tracker Unspecified SQL Injection Vulnerability
Drupal Extended Tracker module is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Drupal Extended Tracker module is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
Drupal Extended Tracker Unspecified SQL Injection Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
Drupal Extended Tracker Unspecified SQL Injection Vulnerability
Solution:
The vendor has released an update to address this issue. Please see the references for more information.
Solution:
The vendor has released an update to address this issue. Please see the references for more information.
References
Drupal Extended Tracker Unspecified SQL Injection Vulnerability
References:
References: