First published: Wed May 09 2007(Updated: )
SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xoops Flashgames Module | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2543 is classified as a moderate severity SQL injection vulnerability.
To fix CVE-2007-2543, update the Flashgames module to a version that addresses this SQL injection vulnerability.
CVE-2007-2543 affects users of the Flashgames module version 1.0.1 for the XOOPS platform.
Attackers can exploit CVE-2007-2543 by sending specially crafted requests targeting the lid parameter in game.php.
CVE-2007-2543 allows remote attackers to execute arbitrary SQL commands, potentially leading to data manipulation or unauthorized access.