---
title: "CVE-2008-3223\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2008-3223?format=md
keywords: index, follow
---

# CVE-2008-3223

Publication date 18 July 2008

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3
allows remote attackers to execute arbitrary SQL commands via vectors
related to "an inappropriate placeholder for 'numeric' fields."

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| drupal | 8.04 LTS hardy | Not in release |
| 7.10 gutsy | Not in release |
| 7.04 feisty | Not affected |
| 6.06 LTS dapper | Not affected |
| drupal5 | 8.04 LTS hardy | Not affected |
| 7.10 gutsy | Not affected |
| 7.04 feisty | Not in release |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3223)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2008-3223)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2008-3223)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2008-3223)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2008-3223>
