CVE-2010-4774: SQL Injection
Published Mar 23, 2011
·Updated
SQL injection vulnerability in pdf.php in AuraCMS 1.62 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-4804 and CVE-2007-4171.
Affected Software
1 affected component
AuraCMS AuraCMS=1.62
Event History
Mar 23, 2011
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4774?
CVE-2010-4774 is considered a critical vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2010-4774?
To fix CVE-2010-4774, it is recommended to update AuraCMS to a version that is not affected by this SQL injection vulnerability.
3
What specific software is affected by CVE-2010-4774?
CVE-2010-4774 specifically affects AuraCMS version 1.62.
4
What type of vulnerability is CVE-2010-4774?
CVE-2010-4774 is an SQL injection vulnerability that allows for the execution of arbitrary SQL commands.
5
What are the potential impacts of CVE-2010-4774?
The potential impacts of CVE-2010-4774 include unauthorized access to the database and manipulation of data.