CVE-2015-7876
The escapeLike function in sqlsrv/database.inc in the Drupal 7 driver for SQL Server and SQL Azure 7.x-1.x before 7.x-1.4 does not properly escape certain characters, which allows remote attackers to execute arbitrary SQL commands via vectors involving…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.48%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The escapeLike function in sqlsrv/database.inc in the Drupal 7 driver for SQL Server and SQL Azure 7.x-1.x before 7.x-1.4 does not properly escape certain characters, which allows remote attackers to execute arbitrary SQL commands via vectors involving a module using the db_like function.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.48% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- drupal 7 driver for sql server and sql azure project/drupal 7 driver for sql server and sql azure
- Source
- cve@mitre.org
References
- http://cgit.drupalcode.org/sqlsrv/commit/?id=2ea0da8
- https://www.drupal.org/node/2569003Patch
- https://www.drupal.org/node/2569005Patch
- https://www.drupal.org/node/2569577Patch
- http://cgit.drupalcode.org/sqlsrv/commit/?id=2ea0da8
- https://www.drupal.org/node/2569003Patch
- https://www.drupal.org/node/2569005Patch
- https://www.drupal.org/node/2569577Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.