CVE-2009-3703: SQL Injection
Multiple SQL injection vulnerabilities in the WP-Forum plugin before 2.4 for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the searchmax parameter in a search action to the default URI, related to wpf.class.php; (2) the forum parameter to an unspecified component, related to wpf.class.php; (3) the topic parameter in a viewforum action to the default URI, related to the removetopic function in wpf.class.php; or the id parameter in a (4) editpost or (5) viewtopic action to the default URI, related to wpf-post.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3703?
The severity of CVE-2009-3703 is high, with a CVSS score of 7.5.
What type of vulnerability is CVE-2009-3703?
CVE-2009-3703 is categorized as an SQL Injection vulnerability.
How do I fix CVE-2009-3703?
To fix CVE-2009-3703, update to the latest version of the WP-Forum plugin that addresses the SQL injection issues.
What are the potential impacts of CVE-2009-3703?
Exploitation of CVE-2009-3703 can allow remote attackers to execute arbitrary SQL commands, potentially compromising database integrity.
Which software is affected by CVE-2009-3703?
CVE-2009-3703 affects the WP-Forum plugin prior to version 2.4 for WordPress.