CVE-2004-2324: SQL Injection
SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database via the (1) table and (2) field parameters in LinkClick.aspx.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2324?
CVE-2004-2324 is considered a critical severity vulnerability due to its potential to allow remote attackers to modify the backend database.
How do I fix CVE-2004-2324?
To fix CVE-2004-2324, upgrade DotNetNuke to version 1.0.11 or later, which addresses this SQL injection vulnerability.
Which versions of DotNetNuke are affected by CVE-2004-2324?
CVE-2004-2324 affects DotNetNuke versions 1.0.6 through 1.0.10d.
What type of vulnerability is CVE-2004-2324?
CVE-2004-2324 is an SQL injection vulnerability that allows unauthorized access to a backend database.
Can CVE-2004-2324 be exploited remotely?
Yes, CVE-2004-2324 can be exploited remotely, allowing attackers to manipulate database content from outside the application.