CVE-2004-2143: SQL Injection
SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in the comremository option.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2143?
CVE-2004-2143 has been classified with a high severity due to its potential for remote SQL injection and arbitrary command execution.
How do I fix CVE-2004-2143?
To fix CVE-2004-2143, update the Mambo Portal to a version later than 4.5.1 or apply relevant patches that address the SQL injection vulnerability.
What software is affected by CVE-2004-2143?
CVE-2004-2143 affects Mambo Portal versions 4.5.1 and earlier.
Can CVE-2004-2143 be exploited remotely?
Yes, CVE-2004-2143 can be exploited remotely by attackers to execute arbitrary SQL commands.
What is the nature of the vulnerability in CVE-2004-2143?
CVE-2004-2143 is an SQL injection vulnerability that allows remote attackers to manipulate SQL queries via the filecatid parameter.