CVE-2009-3337: SQL Injection
Published Sep 24, 2009
·Updated
SQL injection vulnerability in the Freetag (serendipityeventfreetag) plugin before 3.09 for Serendipity (S9Y) allows remote attackers to execute arbitrary SQL commands via an unspecified parameter associated with Meta keywords in a blog entry.
Affected Software
1 affected component
S9Y Serendipity Event Freetag<3.09
Event History
Sep 24, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3337?
CVE-2009-3337 is classified as a high severity vulnerability due to the potential for remote code execution through SQL injection.
2
How do I fix CVE-2009-3337?
To fix CVE-2009-3337, update the Freetag plugin to version 3.09 or later.
3
What type of vulnerability is CVE-2009-3337?
CVE-2009-3337 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
4
Which software is affected by CVE-2009-3337?
CVE-2009-3337 affects the Freetag plugin versions before 3.09 for Serendipity (S9Y).
5
Can CVE-2009-3337 affect my blog?
Yes, if your blog uses an affected version of the Freetag plugin, it could be vulnerable to CVE-2009-3337.