CVE-2009-4070: SQL Injection
Published Nov 24, 2009
·Updated
SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands via unknown vectors.
Affected Software
2 affected components
GForge=4.5.14
GForge=4.7.3
Remediation
Patch Available
Patch Available
Event History
Nov 24, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4070?
CVE-2009-4070 has a high severity as it allows remote attackers to perform arbitrary SQL commands.
2
How do I fix CVE-2009-4070?
To fix CVE-2009-4070, update GForge to the latest patched version.
3
Which versions of GForge are affected by CVE-2009-4070?
CVE-2009-4070 affects GForge versions 4.5.14, 4.7.3, and possibly other versions.
4
Can CVE-2009-4070 be exploited remotely?
Yes, CVE-2009-4070 can be exploited remotely by attackers.
5
What type of vulnerability is CVE-2009-4070?
CVE-2009-4070 is an SQL injection vulnerability.