CVE-2009-2591: SQL Injection
Published Jul 24, 2009
·Updated
SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewannonces action to index.php.
Affected Software
2 affected components
Runcms MyAnnonces
E-Xoopport E-Xoopport=3.1
Event History
Jul 24, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
04:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-2591?
CVE-2009-2591 has a moderate severity rating due to the potential for remote SQL injection attacks.
2
How do I fix CVE-2009-2591?
To fix CVE-2009-2591, you should sanitize user input on the lid parameter in the MyAnnonces module to prevent SQL injection.
3
Which software is affected by CVE-2009-2591?
CVE-2009-2591 affects the MyAnnonces module for E-Xoopport version 3.1.
4
Can CVE-2009-2591 lead to data compromise?
Yes, CVE-2009-2591 can allow attackers to execute arbitrary SQL commands, potentially leading to data compromise.
5
Is CVE-2009-2591 still relevant today?
While CVE-2009-2591 is an older vulnerability, systems using vulnerable software should be assessed for risks as exploits may still exist.