First published: Mon Aug 28 2006(Updated: )
SQL injection vulnerability in edituser.php in Xoops before 2.0.15 allows remote attackers to execute arbitrary SQL commands via the user_avatar parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
E-xoops | <=2.0.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4417 is classified as a critical vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
To mitigate CVE-2006-4417, upgrade Xoops to version 2.0.15 or later where the vulnerability has been patched.
CVE-2006-4417 affects Xoops versions prior to 2.0.15, specifically versions up to and including 2.0.14.
Attackers can exploit CVE-2006-4417 by sending specially crafted requests that manipulate the user_avatar parameter in edituser.php.
Exploitation of CVE-2006-4417 can lead to unauthorized database access, data manipulation, and potential full system compromise.