Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions."
http://www.openwall.com/lists/oss-security/2012/10/30/5
http://www.openwall.com/lists/oss-security/2012/10/29/4
http://drupalcode.org/project/drupal.git/commit/b912710