CVE-2007-6538: SQL Injection
Published Dec 27, 2007
·Updated
SQL injection vulnerability in ing/blocks/mrbs/code/web/viewentry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter.
Affected Software
3 affected components
MRBS MRBS=1.2.3
MRBS MRBS=1.2.5
Moodle moodle
Event History
Dec 27, 2007
CVE Published
11:46 PM
Data Sourced
11:46 PM
DescriptionWeaknessAffected Software
Dec 28, 2007
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6538?
CVE-2007-6538 has been rated as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2007-6538?
To fix CVE-2007-6538, upgrade the MRBS plugin to a version that is not affected, specifically versions later than 1.2.5.
3
What systems are affected by CVE-2007-6538?
CVE-2007-6538 affects MRBS versions 1.2.3 and 1.2.5 when integrated with Moodle.
4
Can CVE-2007-6538 allow attackers to manipulate the database?
Yes, CVE-2007-6538 allows remote attackers to execute arbitrary SQL commands, potentially compromising the database.
5
Is there a way to mitigate CVE-2007-6538 without upgrading?
Mitigation without upgrading is limited; implementing input validation may help reduce risk but does not fully secure the vulnerability.