First published: Thu Jun 09 2005(Updated: )
Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invision Community | =1.1 | |
Invision Community | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1946 is considered a high severity vulnerability due to the risk of arbitrary SQL command execution.
To fix CVE-2005-1946, upgrade Invision Blog to version 1.1.2 Final or later.
CVE-2005-1946 affects Invision Blog versions 1.0 and 1.1 prior to 1.1.2 Final.
Attackers can execute arbitrary SQL commands on the database through multiple entry points.
While it's an older vulnerability, systems running vulnerable versions of Invision Blog without updates may still be at risk.