Unrated severityNVD Advisory· Published May 1, 2009· Updated Apr 23, 2026
CVE-2009-1505
CVE-2009-1505
Description
SQL injection vulnerability in the News Page module 5.x before 5.x-1.2 for Drupal allows remote authenticated users, with News Page nodes create and edit privileges, to execute arbitrary SQL commands via the Include Words (aka keywords) field.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- drupal.org/node/449014nvdPatchVendor Advisory
- www.securityfocus.com/bid/34777nvdPatch
- secunia.com/advisories/34954nvdVendor Advisory
- www.vupen.com/english/advisories/2009/1214nvdVendor Advisory
- osvdb.org/54151nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/50248nvd
News mentions
0No linked articles in our index yet.