An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.
Drupal
Exploit
CVE-2011-2715
NVD
Refer to CVE-2011-2715 NVD advisory