Drupal Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2008-2999 - Vulnerability Database

Drupal Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2008-2999

High
Reference: CVE-2008-2999
Title: Drupal Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

Multiple SQL injection vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.