First published: Sat May 29 2004(Updated: )
Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parameter to content.php, or (3) list parameter to news.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
e107 CMS | =0.615a | |
e107 CMS | =0.615 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2042 has a moderate severity rating due to its potential for SQL injection attacks.
To fix CVE-2004-2042, you should upgrade to a patched version of e107 that addresses the SQL injection vulnerabilities.
CVE-2004-2042 affects e107 CMS versions 0.615 and 0.615a.
CVE-2004-2042 allows remote attackers to execute arbitrary SQL code, potentially exposing sensitive information.
Yes, CVE-2004-2042 can be exploited remotely by attackers targeting specific parameters in the e107 CMS.