CVE-2002-0216: SQL Injection
Published May 3, 2002
·Updated
userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the "uid" parameter.
Affected Software
1 affected component
Xoops Xoops=1.0_rc1
Event History
May 3, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0216?
CVE-2002-0216 has a moderate severity level due to its potential for sensitive information disclosure via SQL injection.
2
How do I fix CVE-2002-0216?
To fix CVE-2002-0216, upgrade to a version of XOOPS that is not vulnerable to SQL injection, specifically versions later than 1.0 RC1.
3
What type of attack is CVE-2002-0216 associated with?
CVE-2002-0216 is associated with SQL injection attacks targeting the "uid" parameter in userinfo.php.
4
What information can be disclosed by exploiting CVE-2002-0216?
Exploiting CVE-2002-0216 can lead to disclosure of sensitive information stored in the database.
5
Is CVE-2002-0216 related to any specific software?
Yes, CVE-2002-0216 specifically affects XOOPS version 1.0 RC1.