Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://drupal.org/node/198162
http://secunia.com/advisories/27932/
http://www.vuxml.org/freebsd/fa708908-a8c7-11dc-b41d-000fb5066b20.html
Insight
The following packages are affected:
drupal5
drupal4
CVE-2007-6299
Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules.
Severity
Classification
-
CVE CVE-2007-6299 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities