CVE-2009-2618: SQL Injection
Published Jul 27, 2009
·Updated
SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results action to modules.php.
Affected Software
1 affected component
MAXdev MDPro=1.083
Event History
Jul 27, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2618?
CVE-2009-2618 is classified as a medium severity SQL injection vulnerability.
2
What software is affected by CVE-2009-2618?
CVE-2009-2618 affects MDPro version 1.083.
3
How do I fix CVE-2009-2618?
To fix CVE-2009-2618, upgrade MDPro to a version that is not vulnerable to SQL injection.
4
What type of vulnerability is CVE-2009-2618?
CVE-2009-2618 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
5
Can CVE-2009-2618 be exploited remotely?
Yes, CVE-2009-2618 can be exploited remotely through a manipulated pollID parameter.