HIGH · 7.5

CVE-2008-6020

SQL injection vulnerability in the Views module 6.x before 6.x-2.2 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to "an exposed filter on CCK tex...

Vulnerability Description

SQL injection vulnerability in the Views module 6.x before 6.x-2.2 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to "an exposed filter on CCK text fields."

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
DrupalViews<= 6.x-2.1
DrupalDrupalAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-6020?

CVE-2008-6020 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in the Views module 6.x before 6.x-2.2 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to "an exposed filter on CCK tex...

How severe is CVE-2008-6020?

CVE-2008-6020 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-6020?

Check the references section above for vendor advisories and patch information. Affected products include: Drupal Views, Drupal Drupal.