CVE-2009-3185: SQL Injection
SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to execute arbitrary SQL commands via the fmid parameter in a view action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3185?
CVE-2009-3185 has been classified as a moderate severity vulnerability due to its potential to allow authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2009-3185?
To fix CVE-2009-3185, you should update to a patched version of the Crazy Star plugin or implement input validation to sanitize the fmid parameter.
Who is affected by CVE-2009-3185?
CVE-2009-3185 affects users of the Crazy Star plugin version 2.0 for Discuz! that allows remote authenticated users to exploit the SQL injection vulnerability.
What type of vulnerability is CVE-2009-3185?
CVE-2009-3185 is classified as an SQL injection vulnerability.
When was CVE-2009-3185 disclosed?
CVE-2009-3185 was disclosed in 2009, highlighting the vulnerability in the Crazy Star plugin.