CVE-2009-0832: SQL Injection
Published Mar 5, 2009
·Updated
SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the CA parameter.
Affected Software
4 affected components
Ausimods E-cart=1.3
PHP-Fusion php-fusion
All of the following
Ausimods E-cart=1.3
PHP-Fusion php-fusion
Event History
Mar 5, 2009
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
08:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·08:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0832?
CVE-2009-0832 has a moderate severity rating due to its potential to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2009-0832?
To fix CVE-2009-0832, sanitize all user inputs and update the E-Cart module to a version that does not contain this vulnerability.
3
What software is affected by CVE-2009-0832?
CVE-2009-0832 specifically affects the E-Cart module version 1.3 for PHP-Fusion.
4
Can CVE-2009-0832 be exploited remotely?
Yes, CVE-2009-0832 can be exploited remotely, allowing attackers to execute SQL commands through the vulnerable parameter.
5
What kind of attacks can be carried out using CVE-2009-0832?
Web application attackers can use CVE-2009-0832 for SQL injection attacks to manipulate or access the database unlawfully.