CVE-2009-0728: SQL Injection
Published Feb 24, 2009
·Updated
SQL injection vulnerability in the MyeGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showpic action to index.php.
Affected Software
6 affected components
MAXdev My Egallery
MAXdev MD-Pro
Postnuke Postnuke
All of the following
MAXdev My Egallery
Any of the following
MAXdev MD-Pro
Postnuke Postnuke
Event History
Feb 24, 2009
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
11:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·11:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0728?
CVE-2009-0728 is classified as a medium-severity vulnerability allowing SQL injection attacks.
2
How do I fix CVE-2009-0728?
To fix CVE-2009-0728, update the My_eGallery module to the latest version where the vulnerability has been patched.
3
What software is affected by CVE-2009-0728?
CVE-2009-0728 affects the My_eGallery module for MAXdev MDPro and PostNuke systems.
4
Can CVE-2009-0728 be exploited remotely?
Yes, CVE-2009-0728 can be exploited remotely through the pid parameter in the showpic action.
5
What are the potential impacts of exploiting CVE-2009-0728?
Exploiting CVE-2009-0728 can allow attackers to execute arbitrary SQL commands, potentially compromising the database.