CVE-2007-1846: SQL Injection
SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter, different vectors than CVE-2006-3341.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1846?
CVE-2007-1846 has a high severity rating due to its potential for allowing attackers to execute arbitrary SQL commands.
How do I fix CVE-2007-1846?
To fix CVE-2007-1846, upgrade the MyAds module to version 2.05 or later where the SQL injection vulnerability is addressed.
What software versions are affected by CVE-2007-1846?
CVE-2007-1846 affects MyAds module versions 2.04jp and earlier for Xoops.
Can CVE-2007-1846 impact my website?
Yes, if you are using the affected versions of the MyAds module, CVE-2007-1846 can allow attackers to compromise your website's database.
What is the cid parameter in CVE-2007-1846?
The cid parameter in CVE-2007-1846 is a user input field that, when manipulated, allows attackers to inject and execute harmful SQL commands.