First published: Tue Jul 14 2009(Updated: )
Multiple SQL injection vulnerabilities in index.php in MIM:InfiniX 1.2.003 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters in a calendar action, or (3) a search term in the search form.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Infinix Mobile devices | <=1.2.003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2451 is considered a critical vulnerability due to its potential for remote SQL command execution.
To fix CVE-2009-2451, upgrade to MIM:InfiniX version 1.2.004 or later, which addresses these SQL injection vulnerabilities.
CVE-2009-2451 affects MIM:InfiniX versions 1.2.003 and possibly earlier versions.
CVE-2009-2451 allows attackers to exploit SQL injection via the month and year parameters and search term in the search form.
Any remote attacker can be affected by CVE-2009-2451 if they can send crafted requests to the vulnerable MIM:InfiniX installations.