CVE-2009-2451: SQL Injection
Multiple SQL injection vulnerabilities in index.php in MIM:InfiniX 1.2.003 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters in a calendar action, or (3) a search term in the search form.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2451?
CVE-2009-2451 is considered a critical vulnerability due to its potential for remote SQL command execution.
How do I fix CVE-2009-2451?
To fix CVE-2009-2451, upgrade to MIM:InfiniX version 1.2.004 or later, which addresses these SQL injection vulnerabilities.
What are the affected versions of MIM:InfiniX for CVE-2009-2451?
CVE-2009-2451 affects MIM:InfiniX versions 1.2.003 and possibly earlier versions.
What attack vectors are associated with CVE-2009-2451?
CVE-2009-2451 allows attackers to exploit SQL injection via the month and year parameters and search term in the search form.
Who can be affected by CVE-2009-2451?
Any remote attacker can be affected by CVE-2009-2451 if they can send crafted requests to the vulnerable MIM:InfiniX installations.