An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names. Reference: https://www.drupal.org/node/1056470
Created drupal6 tracking bugs for this issue: Affects: epel-6 [bug 1799484]
This CVE is for 6.20. EPEL6 has already been at 6.38 for about 4 years (https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-00c45982f6) and in addition several security backports for about a year (https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-67b3f85ea0). Dependent bug is closed. Please close this bug as well.
See previous comment... please close this bug