CVE-2004-1787: SQL Injection
Published Dec 31, 2004
·Updated
SQL injection vulnerability in PostCalendar 4.0.0 allows remote attackers to execute arbitrary SQL commands via search queries.
Affected Software
1 affected component
Postnuke Software Foundation Postcalendar=4.0.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1787?
CVE-2004-1787 is classified as a moderate severity vulnerability due to its ability to allow SQL injection attacks.
2
How do I fix CVE-2004-1787?
To mitigate CVE-2004-1787, upgrade PostCalendar to a version that is not vulnerable to SQL injection.
3
What systems are affected by CVE-2004-1787?
CVE-2004-1787 specifically affects PostCalendar version 4.0.0.
4
Can CVE-2004-1787 be exploited remotely?
Yes, CVE-2004-1787 can be exploited remotely by attackers through search queries.
5
What kind of attacks can CVE-2004-1787 facilitate?
CVE-2004-1787 can allow attackers to execute arbitrary SQL commands in the database.