First published: Wed Jan 04 2012(Updated: )
SQL injection vulnerability in usersettings.php in e107 0.7.26, and possibly other versions before 1.0.0, allows remote attackers to execute arbitrary SQL commands via the username parameter.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
e107 CMS | =0.7.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4921 has a medium severity rating due to the potential for SQL injection attacks.
To fix CVE-2011-4921, upgrade to e107 version 1.0.0 or later where the vulnerability has been addressed.
CVE-2011-4921 affects e107 version 0.7.26 and possibly other versions prior to 1.0.0.
Yes, CVE-2011-4921 can be exploited remotely by attackers to execute arbitrary SQL commands.
The vulnerability in CVE-2011-4921 specifically involves the 'username' parameter in usersettings.php.