Candidate: CVE-2011-4113 PublicDate: 2012-02-17 23:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4113 https://bugzilla.redhat.com/show_bug.cgi?id=751325 Description: SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments." Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_drupal6-mod-views: upstream_drupal6-mod-views: released (2.14-1) hardy_drupal6-mod-views: DNE lucid_drupal6-mod-views: DNE maverick_drupal6-mod-views: DNE natty_drupal6-mod-views: ignored (reached end-of-life) oneiric_drupal6-mod-views: ignored (reached end-of-life) precise_drupal6-mod-views: not-affected (2.14-1) quantal_drupal6-mod-views: not-affected (2.14-1) raring_drupal6-mod-views: not-affected (2.14-1) devel_drupal6-mod-views: not-affected (2.14-1)