CVE-2009-3119: SQL Injection
Published Sep 9, 2009
·Updated
SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the viewid parameter.
Affected Software
2 affected components
X-iweb.ru Download System Msf
PHP-Fusion php-fusion
Event History
Sep 9, 2009
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
10:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-3119?
CVE-2009-3119 has a high severity rating due to its ability to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2009-3119?
To fix CVE-2009-3119, validate and sanitize user input for the view_id parameter to prevent SQL injection.
3
What systems are affected by CVE-2009-3119?
CVE-2009-3119 affects the Download System mSF module for PHP-Fusion.
4
Can CVE-2009-3119 lead to data breaches?
Yes, CVE-2009-3119 can lead to data breaches as it allows attackers to manipulate the database and access sensitive information.
5
What type of security attack is CVE-2009-3119 associated with?
CVE-2009-3119 is associated with SQL injection attacks.