CVE-2009-0427: SQL Injection
Published Feb 5, 2009
·Updated
SQL injection vulnerability in CategoryManager/uploadimagecategory.asp in DMXReady Member Directory Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
Affected Software
1 affected component
DMXReady Member Directory Manager=1.1
Event History
Feb 5, 2009
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0427?
CVE-2009-0427 is classified as a medium severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2009-0427?
To fix CVE-2009-0427, validate and sanitize all user inputs to the cid parameter in the upload_image_category.asp file.
3
What systems are affected by CVE-2009-0427?
CVE-2009-0427 affects DMXReady Member Directory Manager version 1.1 and earlier.
4
Can CVE-2009-0427 allow attackers to manipulate databases?
Yes, CVE-2009-0427 allows attackers to execute arbitrary SQL commands, potentially manipulating the database.
5
What type of vulnerability is CVE-2009-0427?
CVE-2009-0427 is an SQL injection vulnerability.