First published: Fri Nov 18 2005(Updated: )
SQL injection vulnerability in viewcat.php in XOOPS WF-Downloads module 2.05 allows remote attackers to execute arbitrary SQL commands via the list parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
XOOPS WF-Downloads | =2.05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3681 is classified as a high severity vulnerability due to its potential for remote SQL code execution.
To fix CVE-2005-3681, update to a patched version of the XOOPS WF-Downloads module that addresses the SQL injection vulnerability.
CVE-2005-3681 specifically affects XOOPS WF-Downloads module version 2.05.
CVE-2005-3681 allows remote attackers to execute arbitrary SQL commands, potentially compromising the database.
Any website using the vulnerable version of XOOPS WF-Downloads module is at risk from attacks exploiting CVE-2005-3681.