Drupal Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2008-3223 - Vulnerability Database

Drupal Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2008-3223

High
Reference: CVE-2008-3223
Title: Drupal Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to quotan inappropriate placeholder for 39numeric39 fields.quot