CVE-2014-5249
SQL injection vulnerability in the "Biblio self autocomplete" submodule in the Biblio Autocomplete module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0041 (0.4%)
Percentile: 61.4%
EPSS: 2026-05-06
Affects
biblio_autocomplete_project:biblio_autocompleteTechnical description
SQL injection vulnerability in the "Biblio self autocomplete" submodule in the Biblio Autocomplete module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Published: 8/14/2014, 6:47:07 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://www.securityfocus.com/bid/69091
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95146
- https://www.drupal.org/node/2316023
- https://www.drupal.org/node/2316025
- https://www.drupal.org/node/2316717
- http://www.securityfocus.com/bid/69091
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95146
- https://www.drupal.org/node/2316023