CVE-2009-2269: SQL Injection
Published Jul 1, 2009
·Updated
SQL injection vulnerability in Empire CMS 5.1 allows remote attackers to execute arbitrary SQL commands via the bid parameter to the default URI under e/tool/gbook/.
Affected Software
1 affected component
Phome Empire Phome Empire CMS=5.1
Event History
Jul 1, 2009
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2269?
CVE-2009-2269 is classified as a critical vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2009-2269?
Fixing CVE-2009-2269 requires upgrading to a patched version of Empire CMS that addresses this SQL injection vulnerability.
3
Can CVE-2009-2269 be exploited remotely?
Yes, CVE-2009-2269 can be exploited remotely by attackers targeting the bid parameter.
4
Which versions of Empire CMS are affected by CVE-2009-2269?
CVE-2009-2269 specifically affects version 5.1 of Empire CMS.
5
What types of attacks can CVE-2009-2269 facilitate?
CVE-2009-2269 can facilitate SQL injection attacks that may allow unauthorized access to the database and data manipulation.