CVE-2005-2002: SQL Injection
Published Jun 15, 2005
·Updated
SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the userrating parameter.
Affected Software
6 affected components
Mambo Mambo=4.5.2
Mambo Mambo=4.5.0.2
Mambo Mambo=4.5.2.2
Mambo Mambo=4.5.1a-a
Mambo Mambo=4.5.1.3
Mambo Mambo=4.5_1.0.9
Remediation
Patch Available
Event History
Jun 15, 2005
CVE Published
04:00 AM
Jun 20, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2002?
CVE-2005-2002 is a high severity vulnerability that allows remote SQL injection.
2
How do I fix CVE-2005-2002?
To fix CVE-2005-2002, upgrade Mambo to version 4.5.2.3 or later.
3
What are the affected versions for CVE-2005-2002?
CVE-2005-2002 affects Mambo versions 4.5.0.2 through 4.5.2.2.
4
What type of vulnerability is CVE-2005-2002?
CVE-2005-2002 is classified as an SQL injection vulnerability.
5
Can CVE-2005-2002 be exploited without authentication?
Yes, CVE-2005-2002 can be exploited by remote attackers without authentication.