Drupal Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2008-2999
Multiple SQL injection vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.