CVE-2009-4965: SQL Injection
Published Jul 27, 2010
·Updated
SQL injection vulnerability in the AIRware Lexicon (airlexicon) extension 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
2 affected components
Thomas Waggershauser Air Lexicon=0.0.1
Typo3 TYPO3
Event History
Jul 27, 2010
CVE Published
via MITRE·06:39 PM
Data Sourced
via MITRE·06:39 PM
Description
Jul 28, 2010
Data Sourced
02:43 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4965?
CVE-2009-4965 is considered a high-severity vulnerability due to its potential for executing arbitrary SQL commands.
2
How do I fix CVE-2009-4965?
To fix CVE-2009-4965, you should update the AIRware Lexicon extension to a version that is not vulnerable, if available.
3
What software is affected by CVE-2009-4965?
CVE-2009-4965 affects the AIRware Lexicon extension version 0.0.1 for TYPO3.
4
Can CVE-2009-4965 be exploited remotely?
Yes, CVE-2009-4965 can be exploited remotely by attackers to execute SQL commands.
5
What is the nature of the vulnerability in CVE-2009-4965?
CVE-2009-4965 is an SQL injection vulnerability that allows unauthorized SQL command execution.