MEDIUM
SQL injection vulnerability in the News Page module 5.x before 5.x-1.2 for Drupal allows remote authenticated users, with News Page nodes create and edit privileges, to execute arbitrary SQL commands via the Include Words (aka keywords) field
Published May 1, 2009
6.5
MEDIUMCVSS 2.0
EPSS 1.07%
Description
Affected products
Remediation
References (7)
Change history (0)
No recorded changes yet.