First published: Thu Apr 22 2010(Updated: )
Multiple SQL injection vulnerabilities in Community CMS 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to view.php and the (2) a parameter in an event action to calendar.php, reachable through index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invision Community | =0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4794 is considered a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
To mitigate CVE-2009-4794, you should update to the latest version of Community CMS that addresses these SQL injection vulnerabilities.
CVE-2009-4794 affects the view.php and calendar.php components of Community CMS 0.5.
Users of Community CMS version 0.5 are primarily affected by CVE-2009-4794.
CVE-2009-4794 can enable remote SQL injection attacks, potentially leading to unauthorized database access and data manipulation.