CVE-2009-1409: SQL Injection
SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and magicquotesgpc is disabled, allows remote attackers to execute arbitrary SQL commands via the hide parameter, a different vector than CVE-2005-4224 and CVE-2008-5320.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1409?
CVE-2009-1409 is classified as a medium severity SQL injection vulnerability.
How does CVE-2009-1409 work?
CVE-2009-1409 allows remote attackers to execute arbitrary SQL commands via the hide parameter in usersettings.php when certain configurations are set.
What are the affected versions in CVE-2009-1409?
CVE-2009-1409 affects e107 versions 0.7.15 and earlier, as well as versions 0.6.x.
How do I fix CVE-2009-1409?
To fix CVE-2009-1409, upgrade to e107 version 0.7.16 or later, which addresses the SQL injection vulnerability.
What configurations increase the risk of CVE-2009-1409?
The risk of CVE-2009-1409 is increased when the 'Extended User Fields' feature is enabled and 'magic_quotes_gpc' is disabled.