CVE-2008-4148 Information

Description

SQL injection vulnerability in the Mailhandler module 5.x before 5.x-1.4 and 6.x before 6.x-1.4 a module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to composing queries without using the Drupal database API.

Reference

http://drupal.org/node/309769 http://secunia.com/advisories/31877 http://www.securityfocus.com/bid/31230 http://www.vupen.com/english/advisories/2008/2616 https://exchange.xforce.ibmcloud.com/vulnerabilities/45216

Share on: