CVE-2011-4946: SQL Injection
Published Aug 31, 2012
·Updated
SQL injection vulnerability in e107admin/usersextended.php in e107 before 0.7.26 allows remote attackers to execute arbitrary SQL commands via the userfield parameter.
Affected Software
24 affected components
e107 e107=0.7.10
e107 e107=0.7.7
e107 e107=0.7.13
e107 e107=0.7.4
e107 e107=0.7.14
e107 e107=0.7.5
e107 e107=0.7.2
e107 e107=0.7.11
e107 e107=0.7.1
e107 e107=0.7.19
e107 e107=0.7.16
e107 e107<=0.7.24
e107 e107=0.7.15
e107 e107=0.7.22
e107 e107=0.7.12
e107 e107=0.7.17
e107 e107=0.7.8
e107 e107=0.7.20
e107 e107=0.7.9
e107 e107=0.7.0
e107 e107=0.7.18
e107 e107=0.7.6
e107 e107=0.7.21
e107 e107=0.7.3
Remediation
Event History
Aug 31, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4946?
CVE-2011-4946 has a medium severity rating due to its potential for SQL injection attacks.
2
How do I fix CVE-2011-4946?
To fix CVE-2011-4946, upgrade the e107 CMS to version 0.7.26 or later.
3
What systems are affected by CVE-2011-4946?
CVE-2011-4946 affects various versions of e107 CMS prior to 0.7.26.
4
Can CVE-2011-4946 be exploited remotely?
Yes, CVE-2011-4946 can be exploited remotely by attackers using crafted SQL commands.
5
What type of attack does CVE-2011-4946 enable?
CVE-2011-4946 enables SQL injection attacks that allow execution of arbitrary SQL commands.