First published: Wed Apr 13 2005(Updated: )
SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) url_id or (2) entry_id parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Serendipity (S9Y) Freetag Event | =0.3 | |
Serendipity (S9Y) Freetag Event | =0.4 | |
Serendipity (S9Y) Freetag Event | =0.5 | |
Serendipity (S9Y) Freetag Event | =0.5_pl1 | |
Serendipity (S9Y) Freetag Event | =0.6 | |
Serendipity (S9Y) Freetag Event | =0.6_pl1 | |
Serendipity (S9Y) Freetag Event | =0.6_pl2 | |
Serendipity (S9Y) Freetag Event | =0.6_pl3 | |
Serendipity (S9Y) Freetag Event | =0.6_rc1 | |
Serendipity (S9Y) Freetag Event | =0.6_rc2 | |
Serendipity (S9Y) Freetag Event | =0.7 | |
Serendipity (S9Y) Freetag Event | =0.7_beta1 | |
Serendipity (S9Y) Freetag Event | =0.7_beta2 | |
Serendipity (S9Y) Freetag Event | =0.7_beta3 | |
Serendipity (S9Y) Freetag Event | =0.7_beta4 | |
Serendipity (S9Y) Freetag Event | =0.7_rc1 | |
Serendipity (S9Y) Freetag Event | =0.8_beta5 | |
Serendipity (S9Y) Freetag Event | =0.8_beta6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1134 is classified as a critical vulnerability due to its ability to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2005-1134, upgrade to Serendipity version 0.9 or later, which addresses this SQL injection vulnerability.
CVE-2005-1134 affects Serendipity versions 0.8 and earlier.
CVE-2005-1134 is an SQL injection vulnerability that allows attackers to manipulate database queries.
Yes, remote attackers can exploit CVE-2005-1134 by sending specially crafted requests to the affected website.