Description: A vulnerability has been reported in Drupal, which can be exploited by malicious people to conduct SQL injection attacks.
Input passed to the "taxonomy_select_nodes()" function is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Successful exploitation requires that a module that passes unsanitised data to "taxonomy_select_nodes()" is installed. Some of these modules are:
* taxonomy_menu
* ajaxLoader
* ubrowser
The vulnerability is reported in all Drupal 4.7.x versions before 4.7.9 and all Drupal 5.x versions before 5.4.
Solution: Update to version 4.7.9 or 5.4.
Provided and/or discovered by: The vendor credits Nadid Skywalker and Ivan Sergio Borgonovo.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.