First published: Tue Apr 03 2007(Updated: )
SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter, different vectors than CVE-2006-3341.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xoops Malaika System Myads Module | <=2.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1846 has a high severity rating due to its potential for allowing attackers to execute arbitrary SQL commands.
To fix CVE-2007-1846, upgrade the MyAds module to version 2.05 or later where the SQL injection vulnerability is addressed.
CVE-2007-1846 affects MyAds module versions 2.04jp and earlier for Xoops.
Yes, if you are using the affected versions of the MyAds module, CVE-2007-1846 can allow attackers to compromise your website's database.
The cid parameter in CVE-2007-1846 is a user input field that, when manipulated, allows attackers to inject and execute harmful SQL commands.