CVE-2002-2391: SQL Injection
SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2391?
The severity of CVE-2002-2391 is considered high due to the potential for remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2002-2391?
To fix CVE-2002-2391, update the WebChat application to a version that does not contain this vulnerability, or sanitize user input to prevent SQL injection.
What software is affected by CVE-2002-2391?
CVE-2002-2391 affects WebChat 1.5 and XOOPS 1.0.
Can CVE-2002-2391 lead to data breaches?
Yes, CVE-2002-2391 can lead to data breaches as it allows attackers to execute arbitrary SQL commands, potentially exposing sensitive data.
Is CVE-2002-2391 still a risk today?
CVE-2002-2391 can still be a risk if organizations are using outdated versions of the affected software without proper mitigations.