First published: Wed Jul 01 2009(Updated: )
SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the out parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PunBB | ||
Biglle Vote For Us Extension | <=1.0.1 | |
Biglle Vote For Us Extension | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2276 has a high severity rating due to its potential for allowing remote attackers to execute arbitrary SQL commands.
To fix CVE-2009-2276, upgrade to the latest version of the Vote For Us extension that addresses this SQL injection vulnerability.
CVE-2009-2276 affects versions 1.0.1 and earlier of the Vote For Us extension.
CVE-2009-2276 is classified as an SQL injection vulnerability, which can be exploited to manipulate database queries.
Yes, CVE-2009-2276 can lead to data compromise as attackers can execute arbitrary SQL commands, potentially accessing sensitive information.