CVE-2007-2492: SQL Injection
Published May 4, 2007
·Updated
SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a journalcomment action.
Affected Software
1 affected component
Postnuke Software Foundation Postnuke V4bjournal Module=0.99
Event History
May 4, 2007
CVE Published
12:19 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2492?
CVE-2007-2492 is considered a high severity vulnerability due to its potential for allowing unauthorized SQL command execution.
2
How do I fix CVE-2007-2492?
To fix CVE-2007-2492, update to a patched version of the v4bJournal module for PostNuke that addresses the SQL injection risk.
3
Who is affected by CVE-2007-2492?
All users of the v4bJournal module for PostNuke version 0.99 are affected by CVE-2007-2492.
4
What type of vulnerability is CVE-2007-2492?
CVE-2007-2492 is classified as an SQL injection vulnerability.
5
Can CVE-2007-2492 be exploited remotely?
Yes, CVE-2007-2492 can be exploited remotely by authenticated users via the id parameter.