Views Drupal 6.x Security Hole

Events happening in the community are now at Drupal community events on www.drupal.org.
metaltoad's picture

I just want to be sure everyone knows about the Views security vulnerability...

------------DESCRIPTION------------

The Views module provides a flexible method for Drupal site designers to
control how lists of content are presented.

When using an exposed filter on CCK [ http://drupal.org/project/cck ] text
fields with allowed values, Views does not filter the data correctly. This may
allow malicious users to conduct SQL injection [
http://en.wikipedia.org/wiki/SQL_injection ] attacks against the site.

------------VERSIONS AFFECTED------------

  • Versions of Views for Drupal 6.x prior to 6.x-2.2

Drupal core is not affected. If you do not use the Views module, there is
nothing you need to do.

------------SOLUTION------------

Install the latest version.

Also see the Views project page [ http://drupal.org/project/views ].

Portland (Oregon)

Group notifications

This group offers an RSS feed. Or subscribe to these personalized, sitewide feeds: