CVE-2009-2307: SQL Injection
Published Jul 2, 2009
·Updated
SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbitrary SQL commands via the rid parameter in a viewrecords action to modules.php.
Affected Software
2 affected components
MAXdev CWGuestBook<=2.1
MAXdev MD-Pro
Event History
Jul 2, 2009
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
10:30 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-2307?
CVE-2009-2307 has a high severity level due to the potential for remote SQL injection exploitation.
2
How do I fix CVE-2009-2307?
To fix CVE-2009-2307, upgrade the CWGuestBook module to version 2.2 or later.
3
What software is affected by CVE-2009-2307?
CVE-2009-2307 affects CWGuestBook module versions 2.1 and earlier for MAXdev MDPro.
4
Can CVE-2009-2307 be exploited without authentication?
Yes, CVE-2009-2307 can be exploited by unauthenticated remote attackers.
5
What kind of attack can be performed through CVE-2009-2307?
CVE-2009-2307 allows attackers to execute arbitrary SQL commands against the application database.