Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules.
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00258.html
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00190.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/38886
https://exchange.xforce.ibmcloud.com/vulnerabilities/38884
http://www.securityfocus.com/bid/26735
http://sourceforge.net/project/shownotes.php?release_id=559538
http://sourceforge.net/project/shownotes.php?release_id=559532
http://secunia.com/advisories/27973
http://secunia.com/advisories/27951