CVE-2007-2543: SQL Injection
Published May 9, 2007
·Updated
SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter.
Affected Software
1 affected component
Xoops Flashgames Module=1.0.1
Event History
May 9, 2007
CVE Published
01:19 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2543?
CVE-2007-2543 is classified as a moderate severity SQL injection vulnerability.
2
How do I fix CVE-2007-2543?
To fix CVE-2007-2543, update the Flashgames module to a version that addresses this SQL injection vulnerability.
3
Who is affected by CVE-2007-2543?
CVE-2007-2543 affects users of the Flashgames module version 1.0.1 for the XOOPS platform.
4
What attack vectors are associated with CVE-2007-2543?
Attackers can exploit CVE-2007-2543 by sending specially crafted requests targeting the lid parameter in game.php.
5
What impact does CVE-2007-2543 have on affected systems?
CVE-2007-2543 allows remote attackers to execute arbitrary SQL commands, potentially leading to data manipulation or unauthorized access.