CVE-2009-2144: SQL Injection
Published Jun 22, 2009
·Updated
SQL injection vulnerability in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
66 affected components
edgewall Firestats<=1.6.1
edgewall Firestats=0.9.0-beta
edgewall Firestats=0.9.1-beta
edgewall Firestats=0.9.2-beta
edgewall Firestats=0.9.3-beta
edgewall Firestats=0.9.4-beta
edgewall Firestats=0.9.5-beta
edgewall Firestats=0.9.6-beta
edgewall Firestats=0.9.7-beta
edgewall Firestats=0.9.8-beta
edgewall Firestats=0.9.9
edgewall Firestats=1.0
edgewall Firestats=1.0.0-rc1
edgewall Firestats=1.0.1-rc2
edgewall Firestats=1.0.2-rc3
edgewall Firestats=1.0.2-stable
edgewall Firestats=1.1.1-rc1
edgewall Firestats=1.1.2-rc2
edgewall Firestats=1.1.3-rc3
edgewall Firestats=1.1.3-rc4
edgewall Firestats=1.1.4-rc5
edgewall Firestats=1.1.5-stable
edgewall Firestats=1.1.6-stable
edgewall Firestats=1.1.7-stable
edgewall Firestats=1.1.8-stable
edgewall Firestats=1.2.0-beta
edgewall Firestats=1.2.1-rc1
edgewall Firestats=1.2.2-rc2
edgewall Firestats=1.2.3-rc3
edgewall Firestats=1.2.4-stable
edgewall Firestats=1.3.0-beta
edgewall Firestats=1.3.1-beta
edgewall Firestats=1.3.2-beta
edgewall Firestats=1.3.3-beta
edgewall Firestats=1.3.4-rc1
edgewall Firestats=1.3.5-rc2
edgewall Firestats=1.3.6-stable
edgewall Firestats=1.4
edgewall Firestats=1.4.0-beta
edgewall Firestats=1.4.1-beta
edgewall Firestats=1.4.2-beta
edgewall Firestats=1.4.3-rc1
edgewall Firestats=1.4.4-stable
edgewall Firestats=1.5
edgewall Firestats=1.5.0-beta
edgewall Firestats=1.5.1-beta
edgewall Firestats=1.5.2-beta
edgewall Firestats=1.5.3-rc1
edgewall Firestats=1.5.4-rc2
edgewall Firestats=1.5.5-rc3
edgewall Firestats=1.5.6-beta
edgewall Firestats=1.5.7-rc1
edgewall Firestats=1.5.8-rc2
edgewall Firestats=1.5.9-rc3
edgewall Firestats=1.5.10-rc4
edgewall Firestats=1.5.12-stable
edgewall Firestats=1.6
edgewall Firestats=1.6.0-stable
edgewall Firestats=1.6.0-beta1
edgewall Firestats=1.6.0-beta2
edgewall Firestats=11.5.11-stable
firestats FireStats=1.6.0-rc1
firestats FireStats=1.6.0-rc2
firestats FireStats=1.6.0-rc3
firestats FireStats=1.6.0-rc4
WordPress WordPress
Remediation
Patch Available
Event History
Jun 22, 2009
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
02:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-2144?
CVE-2009-2144 has a high severity due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2009-2144?
To fix CVE-2009-2144, you should update the FireStats plugin to version 1.6.2-stable or later.
3
Which versions are affected by CVE-2009-2144?
CVE-2009-2144 affects FireStats versions prior to 1.6.2-stable, including all beta versions listed before this stable release.
4
Can CVE-2009-2144 be exploited remotely?
Yes, CVE-2009-2144 can be exploited remotely by attackers to execute arbitrary SQL commands through the vulnerability.
5
What is the nature of the vulnerability in CVE-2009-2144?
CVE-2009-2144 is an SQL injection vulnerability that allows unauthorized database access and manipulation.