Schema API used an inappropriate placeholder for ‘numeric’ fields enabling SQL injection when user-supplied data was used for such fields. This issue affects Drupal 6 only.
Part of security release SA-2008-044
This vulnerability affects the following application versions:
- Drupal 6.0
- Drupal 6.1
- Drupal 6.2