CVE-2012-4479
high
CVSS v3
—
CVSS v2
7.5
VIR risk
7.5
Description
SQL injection vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://drupal.org/node/1679442
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| david_alkire | drag_\&_drop_gallery | 6.x-1.5 | |
| drupal | drupal | - | |
References
CWEs
CWE-89
Verify integrity in audit chain (admin only). AS-IS.