CVE-2007-1135: SQL Injection
Published Feb 27, 2007
·Updated
Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2) id[0] or other id array index parameter to filecheck.php.
Affected Software
1 affected component
Sourceforge Webmplayer<=0.6.1-alpha
Remediation
Event History
Feb 27, 2007
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1135?
The severity of CVE-2007-1135 is considered high due to the potential for remote SQL injection attacks.
2
How do I fix CVE-2007-1135?
To fix CVE-2007-1135, users should upgrade WebMplayer to version 0.6.1-Alpha or later.
3
What systems are affected by CVE-2007-1135?
CVE-2007-1135 affects all versions of WebMplayer prior to 0.6.1-Alpha.
4
What kind of attacks can be executed due to CVE-2007-1135?
CVE-2007-1135 allows remote attackers to execute arbitrary SQL commands, potentially compromising database integrity.
5
Are there known exploits for CVE-2007-1135?
Yes, there are known exploits for CVE-2007-1135 that target the SQL injection vulnerabilities in WebMplayer.