CVE-2004-1654: SQL Injection
Published Sep 1, 2004
·Updated
SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via caltemplate.
Affected Software
5 affected components
phpWebSite phpWebSite=0.9.3.4
phpWebSite phpWebSite=0.8.2
phpWebSite phpWebSite=0.9.3
phpWebSite phpWebSite=0.8.3
phpWebSite phpWebSite=0.7.3
Remediation
Patch Available
Patch Available
Event History
Sep 1, 2004
CVE Published
04:00 AM
Feb 20, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1654?
CVE-2004-1654 is classified as a high severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2004-1654?
To fix CVE-2004-1654, upgrade to phpWebsite version 0.9.5 or later, which contains the necessary security patches.
3
What systems are affected by CVE-2004-1654?
CVE-2004-1654 affects phpWebsite versions 0.9.3-4 and earlier, including 0.9.3, 0.8.2, 0.8.3, and 0.7.3.
4
What type of attack is possible due to CVE-2004-1654?
CVE-2004-1654 allows remote attackers to execute arbitrary SQL commands, potentially compromising the database.
5
Is CVE-2004-1654 a zero-day vulnerability?
No, CVE-2004-1654 is not a zero-day vulnerability as it was disclosed publicly in 2004.