CVE-2009-4621: SQL Injection
SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to forummission.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4621?
CVE-2009-4621 is considered a critical vulnerability due to its potential for remote code execution through SQL injection.
How do I fix CVE-2009-4621?
To fix CVE-2009-4621, upgrade the JiangHu Inn plugin to version 1.2 or later where the SQL injection vulnerability is patched.
Who is affected by CVE-2009-4621?
CVE-2009-4621 affects users of the JiangHu Inn plugin version 1.1 and earlier for Discuz!.
What type of vulnerability is CVE-2009-4621?
CVE-2009-4621 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
What action can attackers perform with CVE-2009-4621?
Attackers can manipulate the 'id' parameter in a show action to gain unauthorized access to the database.