CVE-2009-4360: SQL Injection
Published Dec 20, 2009
·Updated
SQL injection vulnerability in modules/content/index.php in the Content module 0.5 for XOOPS allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Affected Software
2 affected components
Handcoders Content Module=0.5
Xoops Xoops
Event History
Dec 20, 2009
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
02:30 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4360?
CVE-2009-4360 is considered to have a medium severity due to its potential for SQL injection attacks.
2
How do I fix CVE-2009-4360?
To fix CVE-2009-4360, update the Content module to a newer version that addresses this vulnerability.
3
What type of vulnerability is CVE-2009-4360?
CVE-2009-4360 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
4
Who is affected by CVE-2009-4360?
CVE-2009-4360 affects users of the Content module version 0.5 for XOOPS.
5
What can attackers do with CVE-2009-4360?
Attackers exploiting CVE-2009-4360 can inject arbitrary web scripts or HTML via the id parameter.