First published: Fri Jul 24 2009(Updated: )
SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewannonces action to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Runcms Myannonces | ||
E-xoopport | =3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2591 has a moderate severity rating due to the potential for remote SQL injection attacks.
To fix CVE-2009-2591, you should sanitize user input on the lid parameter in the MyAnnonces module to prevent SQL injection.
CVE-2009-2591 affects the MyAnnonces module for E-Xoopport version 3.1.
Yes, CVE-2009-2591 can allow attackers to execute arbitrary SQL commands, potentially leading to data compromise.
While CVE-2009-2591 is an older vulnerability, systems using vulnerable software should be assessed for risks as exploits may still exist.