CVE-2009-1842: SQL Injection
Published Jun 1, 2009
·Updated
SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header.
Affected Software
1 affected component
Phpnuke Php-nuke=8.0
Event History
Jun 1, 2009
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1842?
CVE-2009-1842 is considered a medium severity vulnerability due to its potential for SQL injection and remote code execution.
2
How do I fix CVE-2009-1842?
To fix CVE-2009-1842, upgrade PHP-Nuke to a newer version that has patched the SQL injection vulnerability.
3
Which versions of PHP-Nuke are affected by CVE-2009-1842?
CVE-2009-1842 specifically affects PHP-Nuke version 8.0.
4
What is the attack vector for CVE-2009-1842?
The attack vector for CVE-2009-1842 is the HTTP Referer header, which allows remote attackers to execute arbitrary SQL commands.
5
Can CVE-2009-1842 allow full server compromise?
Yes, CVE-2009-1842 can lead to full server compromise if exploited successfully due to unauthorized SQL command execution.