CVE-2010-4861: SQL Injection
Published Oct 5, 2011
·Updated
SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.
Affected Software
1 affected component
webSPELL Webspell=4.2.1
Remediation
Patch Available
Event History
Oct 5, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4861?
CVE-2010-4861 is rated as a high severity vulnerability due to its potential to allow arbitrary SQL command execution.
2
How do I fix CVE-2010-4861?
To fix CVE-2010-4861, you should update webSPELL to version 4.2.2 or later which addresses this vulnerability.
3
What type of vulnerability is CVE-2010-4861?
CVE-2010-4861 is classified as an SQL injection vulnerability affecting the asearch.php file in webSPELL.
4
Who is affected by CVE-2010-4861?
CVE-2010-4861 affects all users of webSPELL version 4.2.1.
5
Can CVE-2010-4861 be exploited remotely?
Yes, CVE-2010-4861 can be exploited remotely by attackers via the search parameter.