CVE-2009-1506: SQL Injection
Published May 1, 2009
·Updated
SQL injection vulnerability in classes/Xp.php in eLitius 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to banner-details.php.
Affected Software
1 affected component
Intelliants Elitius=1.0
Event History
May 1, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1506?
CVE-2009-1506 is classified as a high severity vulnerability due to the risk of arbitrary SQL command execution.
2
How do I fix CVE-2009-1506?
To fix CVE-2009-1506, sanitize and validate the input for the 'id' parameter in the banner-details.php file.
3
What software is affected by CVE-2009-1506?
CVE-2009-1506 affects eLitius version 1.0.
4
Can CVE-2009-1506 lead to data compromise?
Yes, CVE-2009-1506 can lead to data compromise as attackers can execute arbitrary SQL commands.
5
Who can exploit CVE-2009-1506?
Remote attackers can exploit CVE-2009-1506 by manipulating the 'id' parameter in requests to banner-details.php.