CVE-2009-2385: SQL Injection
SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 for Simple Machines Forum (SMF) allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to index.php. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2385?
CVE-2009-2385 has a medium severity level due to its potential for SQL injection and remote exploitation.
How do I fix CVE-2009-2385?
To fix CVE-2009-2385, update the Member Awards component to a version that does not have this vulnerability.
What software is affected by CVE-2009-2385?
CVE-2009-2385 specifically affects version 1.0.2 of the Member Awards component for Simple Machines Forum.
Can CVE-2009-2385 allow for data theft?
Yes, CVE-2009-2385 can allow attackers to execute arbitrary SQL commands, which may lead to data theft.
Is CVE-2009-2385 widely exploited?
While exploitation of CVE-2009-2385 is possible, its prevalence is limited to setups using the vulnerable Member Awards component.