CVE-2004-1836: SQL Injection
Published Dec 31, 2004
·Updated
SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.
Affected Software
3 affected components
Invision Power Services Invision Power Top Site List=1.0
Invision Power Services Invision Power Top Site List=1.1
Invision Power Services Invision Power Top Site List=1.1_rc2
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1836?
CVE-2004-1836 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2004-1836?
To fix CVE-2004-1836, upgrade to a patched version of Invision Power Top Site List that addresses the SQL injection vulnerability.
3
What are the affected versions in CVE-2004-1836?
CVE-2004-1836 affects Invision Power Top Site List versions 1.0, 1.1, and 1.1 RC 2.
4
What vulnerability type is CVE-2004-1836?
CVE-2004-1836 is an SQL injection vulnerability that allows remote execution of arbitrary SQL commands.
5
Who is impacted by CVE-2004-1836?
Remote attackers can exploit CVE-2004-1836 to compromise systems running vulnerable versions of Invision Power Top Site List.