CVE-2007-1034: SQL Injection
Published Feb 21, 2007
·Updated
SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.
Affected Software
1 affected component
PHP-Nuke Emporium Module<=2.3.0
Event History
Feb 21, 2007
CVE Published
11:28 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1034?
CVE-2007-1034 is considered a critical severity vulnerability due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2007-1034?
To fix CVE-2007-1034, upgrade the Emporium module for PHP-Nuke to version 2.3.1 or later.
3
Who is affected by CVE-2007-1034?
Users of Emporium version 2.3.0 and earlier for PHP-Nuke are affected by CVE-2007-1034.
4
What type of vulnerability is CVE-2007-1034?
CVE-2007-1034 is classified as an SQL injection vulnerability.
5
What can attackers do with CVE-2007-1034?
Attackers exploiting CVE-2007-1034 can execute arbitrary SQL commands on the database.