CVE-2005-1946: SQL Injection
Published Jun 9, 2005
·Updated
Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action.
Affected Software
2 affected components
Invision Power Services Invision Community Blog=1.0
Invision Power Services Invision Community Blog=1.1
Remediation
Event History
Jun 9, 2005
CVE Published
04:00 AM
Jun 14, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1946?
CVE-2005-1946 is considered a high severity vulnerability due to the risk of arbitrary SQL command execution.
2
How do I fix CVE-2005-1946?
To fix CVE-2005-1946, upgrade Invision Blog to version 1.1.2 Final or later.
3
What software is affected by CVE-2005-1946?
CVE-2005-1946 affects Invision Blog versions 1.0 and 1.1 prior to 1.1.2 Final.
4
What can attackers achieve with CVE-2005-1946?
Attackers can execute arbitrary SQL commands on the database through multiple entry points.
5
Is CVE-2005-1946 still a risk today?
While it's an older vulnerability, systems running vulnerable versions of Invision Blog without updates may still be at risk.