CVE-2012-1638
Published Sep 19, 2012
Last updated 12 years ago
Overview
- Description
- SQL injection vulnerability in the Search Autocomplete module before 7.x-2.1 for Drupal allows remote authenticated users with the "use search_autocomplete" permission to execute arbitrary SQL commands via unspecified vectors.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6
- Impact score
- 6.4
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:dominique_clause:search_autocomplete:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B4A9DB68-5744-4142-B777-D481FD13B741", "versionEndIncluding": "7.x-2.0" }, { "criteria": "cpe:2.3:a:dominique_clause:search_autocomplete:5.x-1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F1E2D5A0-043E-4D20-BF17-4D70097BA4E6" }, { "criteria": "cpe:2.3:a:dominique_clause:search_autocomplete:5.x-1.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "29CEE012-5807-4A19-887C-CDAAB04534EB" }, { "criteria": "cpe:2.3:a:dominique_clause:search_autocomplete:5.x-1.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B75B21DB-F6AC-4021-91A3-E1D6CE888C3B" }, { "criteria": "cpe:2.3:a:dominique_clause:search_autocomplete:5.x-1.x:dev:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ACC01BD4-13D1-4D6A-8621-8CA940D3B659" }, { "criteria": "cpe:2.3:a:dominique_clause:search_autocomplete:6.x-1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4EA570BF-42DD-433D-92E6-16CECEE4805F" }, { "criteria": "cpe:2.3:a:dominique_clause:search_autocomplete:6.x-1.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C71264E6-341D-46CF-BE29-890C469EEEBD" }, { "criteria": "cpe:2.3:a:dominique_clause:search_autocomplete:6.x-2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BB97AC51-CEC9-460D-87E3-2EAC34708650" }, { "criteria": "cpe:2.3:a:dominique_clause:search_autocomplete:6.x-2.0:alpha1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "556041BC-BBBA-4DA9-9B87-C0F2EE28B95B" }, { "criteria": "cpe:2.3:a:dominique_clause:search_autocomplete:6.x-2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CCE1512C-A554-4D5B-9920-681C279E361A" }, { "criteria": "cpe:2.3:a:dominique_clause:search_autocomplete:6.x-2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3A422FB1-A8B7-417B-AB4A-84613644C46B" }, { "criteria": "cpe:2.3:a:dominique_clause:search_autocomplete:6.x-2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B036707-3BA8-4E81-B85B-29D6A9A713C1" }, { "criteria": "cpe:2.3:a:dominique_clause:search_autocomplete:7.x-1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4D69DBD9-BD60-417A-8726-0F96559DF349" }, { "criteria": "cpe:2.3:a:dominique_clause:search_autocomplete:7.x-1.0:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D01C3118-EFCC-4B27-B94F-548D27CF9A49" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF" } ], "operator": "OR" } ], "operator": "AND" } ]