>> Acidfree Module for Drupal Node Title Handling Remote SQL Injection Vulnerability
Title : Acidfree Module for Drupal Node Title Handling Remote SQL Injection Vulnerability VUPEN ID : VUPEN/ADV-2007-0313 CVE ID : CVE-2007-0507
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-24
Technical Description
A vulnerability has been identified in Acidfree (module for Drupal), which could be exploited by attackers to execute arbitrary SQL commands. This issue is due to an input validation error when processing node titles, which could be exploited by malicious users with "create acidfree albums" privileges to conduct SQL injection attacks.