Lucene search

K
mageiaGentoo FoundationMGASA-2014-0423
HistoryOct 26, 2014 - 12:23 a.m.

Updated drupal packages fix security vulnerability

2014-10-2600:23:09
Gentoo Foundation
advisories.mageia.org
24

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.975 High

EPSS

Percentile

100.0%

An SQL Injection issue exists in Drupal before 7.32 due to the way the Drupal core handles prepared statements. A malicious user can inject arbitrary SQL queries, and thereby completely control the Drupal site. This vulnerability can be exploited by remote attackers without any kind of authentication required (CVE-2014-3704).

OSVersionArchitecturePackageVersionFilename
Mageia3noarchdrupal< 7.32-1drupal-7.32-1.mga3
Mageia4noarchdrupal< 7.32-1drupal-7.32-1.mga4

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.975 High

EPSS

Percentile

100.0%