CVE-2010-3601: SQL Injection
Published Sep 24, 2010
·Updated
SQL injection vulnerability in index.php in ibPhotohost 1.1.2 allows remote attackers to execute arbitrary SQL commands via the img parameter.
Affected Software
1 affected component
Invisionpower Ibphotohost=1.1.2
Event History
Sep 24, 2010
CVE Published
via MITRE·07:44 PM
Data Sourced
via MITRE·07:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3601?
CVE-2010-3601 is considered a high severity SQL injection vulnerability.
2
How do I fix CVE-2010-3601?
To fix CVE-2010-3601, upgrade ibPhotohost to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2010-3601?
CVE-2010-3601 is an SQL injection vulnerability.
4
What impact does CVE-2010-3601 have on affected systems?
CVE-2010-3601 allows remote attackers to execute arbitrary SQL commands on affected systems.
5
In which version of ibPhotohost is CVE-2010-3601 present?
CVE-2010-3601 is present in ibPhotohost version 1.1.2.