CVE-2007-2685: SQL Injection
Published May 21, 2007
·Updated
Multiple SQL injection vulnerabilities in index.php in Jetbox CMS 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) login parameter.
Affected Software
1 affected component
Jetbox Jetbox CMS=2.1
Event History
May 21, 2007
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2685?
CVE-2007-2685 is considered a critical vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2007-2685?
To fix CVE-2007-2685, you should update Jetbox CMS to the latest version that addresses these SQL injection vulnerabilities.
3
What versions of Jetbox CMS are affected by CVE-2007-2685?
CVE-2007-2685 affects Jetbox CMS version 2.1.
4
Can CVE-2007-2685 lead to data breaches?
Yes, CVE-2007-2685 can lead to data breaches as it allows attackers to manipulate and extract sensitive information from the database.
5
What parameters are exploited in CVE-2007-2685?
The vulnerable parameters in CVE-2007-2685 are the 'view' and 'login' parameters in index.php.