CVE-2009-3150: SQL Injection
Published Sep 10, 2009
·Updated
SQL injection vulnerability in index.php in Multi Website 1.5 allows remote attackers to execute arbitrary SQL commands via the Browse parameter in a vote action.
Affected Software
1 affected component
Multi-website Multi Website=1.5
Event History
Sep 10, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3150?
CVE-2009-3150 has been classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2009-3150?
To fix CVE-2009-3150, sanitize and validate user input for the Browse parameter to prevent SQL injection attacks.
3
Can CVE-2009-3150 be exploited remotely?
Yes, CVE-2009-3150 can be exploited remotely to execute arbitrary SQL commands.
4
Which software versions are affected by CVE-2009-3150?
CVE-2009-3150 affects Multi Website version 1.5.
5
What are the potential consequences of exploiting CVE-2009-3150?
Exploiting CVE-2009-3150 could allow attackers to gain unauthorized access to the database and manipulate data.