First published: Thu Jul 05 2007(Updated: )
Multiple SQL injection vulnerabilities in akocomment allow remote attackers to execute arbitrary SQL commands via the (1) acparentid or (2) acitemid parameter to an unspecified component, different vectors than CVE-2006-1421.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arthur Konze Webdesign Akocomment |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3573 is considered a high severity vulnerability due to its potential for remote SQL injection attacks.
To fix CVE-2007-3573, update to the latest version of Akocomment that addresses these SQL injection vulnerabilities.
CVE-2007-3573 affects the acparentid and acitemid parameters, which can be exploited to execute arbitrary SQL commands.
Yes, if exploited, CVE-2007-3573 can allow attackers to compromise sensitive data stored in the database.
All versions of Akocomment prior to the security patch that addressed CVE-2007-3573 are considered vulnerable.