CVE-2004-2322: SQL Injection
Published Dec 31, 2004
·Updated
SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3-2 allows remote attackers to execute arbitrary SQL queries, as demonstrated using the ANNid parameter to the announce module.
Affected Software
6 affected components
phpWebSite phpWebSite=0.9.1
phpWebSite phpWebSite=0.9.2
phpWebSite phpWebSite=0.9.3.1
phpWebSite phpWebSite=0.9.2.1
phpWebSite phpWebSite=0.9.3
phpWebSite phpWebSite=0.9.0
Event History
Dec 31, 2004
CVE Published
05:00 AM
Aug 16, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2322?
CVE-2004-2322 is considered a high severity vulnerability due to the potential for remote code execution through SQL injection.
2
How do I fix CVE-2004-2322?
To fix CVE-2004-2322, upgrade phpWebSite to version 0.9.3-2 or later which addresses this vulnerability.
3
Which versions of phpWebSite are affected by CVE-2004-2322?
CVE-2004-2322 affects phpWebSite versions 0.9.0 to 0.9.3.1.
4
What kind of attacks can exploit CVE-2004-2322?
CVE-2004-2322 can be exploited to execute arbitrary SQL queries against the database.
5
Are there any mitigating factors for CVE-2004-2322?
Mitigating factors for CVE-2004-2322 include restricting access to phpWebSite modules and employing a web application firewall.