CVE-2010-4870: SQL Injection
Published Oct 7, 2011
·Updated
SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parameter.
Affected Software
1 affected component
bloofox bloofoxCMS=0.3.5
Event History
Oct 7, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4870?
CVE-2010-4870 is classified as a high severity vulnerability due to the potential for remote SQL command execution.
2
How do I fix CVE-2010-4870?
To fix CVE-2010-4870, it is recommended to update BloofoxCMS to a newer version that addresses this SQL injection vulnerability.
3
Who is affected by CVE-2010-4870?
CVE-2010-4870 specifically affects users of BloofoxCMS version 0.3.5.
4
What type of vulnerability is CVE-2010-4870?
CVE-2010-4870 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
5
What parameters are exploited in CVE-2010-4870?
The vulnerability in CVE-2010-4870 can be exploited via the 'gender' parameter in index.php.