First published: Tue Feb 27 2007(Updated: )
Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2) id[0] or other id array index parameter to filecheck.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sourceforge Webmplayer | <=0.6.1-alpha |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-1135 is considered high due to the potential for remote SQL injection attacks.
To fix CVE-2007-1135, users should upgrade WebMplayer to version 0.6.1-Alpha or later.
CVE-2007-1135 affects all versions of WebMplayer prior to 0.6.1-Alpha.
CVE-2007-1135 allows remote attackers to execute arbitrary SQL commands, potentially compromising database integrity.
Yes, there are known exploits for CVE-2007-1135 that target the SQL injection vulnerabilities in WebMplayer.