First published: Wed Feb 11 2009(Updated: )
SQL injection vulnerability in FlexCMS allows remote attackers to execute arbitrary SQL commands via the catId parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealFlex RealWin |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-0534 is considered to be high due to its potential for remote SQL execution.
To fix CVE-2009-0534, you should validate and sanitize the input for the catId parameter to prevent SQL injection.
CVE-2009-0534 affects all versions of FlexCMS.
The impact of CVE-2009-0534 includes the possibility of an attacker executing arbitrary SQL commands on the database.
Yes, CVE-2009-0534 can be exploited by unauthenticated remote attackers.