First published: Sun Dec 20 2009(Updated: )
SQL injection vulnerability in modules/content/index.php in the Content module 0.5 for XOOPS allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Handcoders Content Module | =0.5 | |
Xoops Xm Memberstats |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4360 is considered to have a medium severity due to its potential for SQL injection attacks.
To fix CVE-2009-4360, update the Content module to a newer version that addresses this vulnerability.
CVE-2009-4360 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
CVE-2009-4360 affects users of the Content module version 0.5 for XOOPS.
Attackers exploiting CVE-2009-4360 can inject arbitrary web scripts or HTML via the id parameter.