CVE-2009-0426: SQL Injection
SQL injection vulnerability in CategoryManager/uploadimagecategory.asp in DMXReady Classified Listings Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0426?
CVE-2009-0426 is considered to have a medium severity due to the potential for SQL injection attacks that can lead to unauthorized database access.
How do I fix CVE-2009-0426?
To fix CVE-2009-0426, sanitize and validate user inputs for the cid parameter to prevent SQL injection.
What software is affected by CVE-2009-0426?
CVE-2009-0426 affects DMXReady Classified Listings Manager version 1.1 and earlier.
What types of attacks can CVE-2009-0426 allow?
CVE-2009-0426 can allow remote attackers to execute arbitrary SQL commands against the database.
How can I determine if my system is vulnerable to CVE-2009-0426?
You can determine if your system is vulnerable to CVE-2009-0426 by checking if you are using DMXReady Classified Listings Manager version 1.1 or earlier and testing the cid parameter for SQL injection flaws.