CVE-2007-5104: SQL Injection
Published Sep 26, 2007
·Updated
SQL injection vulnerability in index.php in the Arcade module in bcoos 1.0.10 allows remote attackers to execute arbitrary SQL commands via the gid parameter in a playgame action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
1 affected component
bcoos bcoos=1.0.10
Event History
Sep 26, 2007
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5104?
CVE-2007-5104 has a medium severity level due to its ability to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2007-5104?
To fix CVE-2007-5104, you should validate and sanitize the gid parameter in the play_game action to prevent SQL injection.
3
Which versions of Bcoos are affected by CVE-2007-5104?
CVE-2007-5104 affects Bcoos version 1.0.10.
4
What type of vulnerability is CVE-2007-5104?
CVE-2007-5104 is classified as an SQL injection vulnerability.
5
What module is vulnerable in CVE-2007-5104?
The Arcade module in Bcoos 1.0.10 is vulnerable as described in CVE-2007-5104.