CVE-2010-4942: SQL Injection
Published Oct 9, 2011
·Updated
SQL injection vulnerability in location.php in the eCal module in E-Xoopport Samsara 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the lid parameter.
Affected Software
4 affected components
E-Xoopport Samsara<=3.1
E-Xoopport Samsara=3.0-rc1
E-Xoopport Samsara=3.0
E-Xoopport Samsara=3.0-beta
Event History
Oct 9, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4942?
CVE-2010-4942 is considered a high severity vulnerability due to its potential for remote SQL command execution.
2
How do I fix CVE-2010-4942?
To fix CVE-2010-4942, upgrade to a version of E-Xoopport Samsara later than 3.1, which includes a patch for this vulnerability.
3
What systems are affected by CVE-2010-4942?
CVE-2010-4942 affects E-Xoopport Samsara versions 3.1 and earlier, including specific pre-release versions.
4
Can CVE-2010-4942 be exploited by unauthenticated users?
Yes, CVE-2010-4942 can be exploited by unauthenticated remote attackers, making it particularly dangerous.
5
What kind of attacks can result from CVE-2010-4942?
Exploitation of CVE-2010-4942 can lead to arbitrary SQL command execution, potentially compromising the database.