First published: Mon Mar 28 2005(Updated: )
Multiple SQL injection vulnerabilities in exoops may allow remote attackers to execute arbitrary SQL commands via (1) the viewcat parameter to index.php or (2) the artid parameter in the viewarticle action for index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
E-xoops |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0911 is classified as a high severity vulnerability due to the potential for remote SQL injection attacks.
To fix CVE-2005-0911, update the exoops software to the latest version that addresses the SQL injection vulnerabilities.
CVE-2005-0911 highlights vulnerabilities in the viewcat parameter of index.php and the artid parameter in the viewarticle action of index.php.
Any application using vulnerable versions of e-xoops that allows the input of the specified parameters is affected by CVE-2005-0911.
CVE-2005-0911 can be exploited to execute arbitrary SQL commands, compromising the database and potentially exposing sensitive data.