CVE-2009-4394: SQL Injection
Published Dec 22, 2009
·Updated
SQL injection vulnerability in the Random Prayer 2 (steprayer2) extension 0.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
3 affected components
Fr.simon Rundell Ste Prayer2<=0.0.3
Fr.simon Rundell Ste Prayer2=0.0.2
Typo3 TYPO3
Event History
Dec 22, 2009
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
11:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4394?
CVE-2009-4394 is considered a high severity vulnerability due to the potential for arbitrary SQL command execution.
2
How do I fix CVE-2009-4394?
To address CVE-2009-4394, update the Random Prayer 2 extension to version 0.0.4 or later.
3
What applications are affected by CVE-2009-4394?
CVE-2009-4394 affects the Random Prayer 2 extension versions 0.0.3 and earlier for TYPO3.
4
Can CVE-2009-4394 lead to unauthorized data access?
Yes, CVE-2009-4394 can allow remote attackers to execute SQL commands, potentially leading to unauthorized data access.
5
What is the nature of CVE-2009-4394's vulnerability?
CVE-2009-4394 is an SQL injection vulnerability that enables execution of arbitrary SQL commands through unspecified vectors.