Security Advisory

CVE-2012-1626

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-09-20 01:00:00
Last updated 2024-08-06 19:01:02
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer Date Tools" privilege to execute arbitrary SQL commands via unspecified vectors.