CVE-2011-5022: SQL Injection
Published Dec 29, 2011
·Updated
SQL injection vulnerability in search.php in Pligg CMS 1.1.2 allows remote attackers to execute arbitrary SQL commands via the status parameter.
Affected Software
1 affected component
Pligg Pligg CMS=1.1.2
Event History
Dec 29, 2011
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-5022?
CVE-2011-5022 is classified as a high severity vulnerability due to its potential for remote code execution via SQL injection.
2
How do I fix CVE-2011-5022?
To fix CVE-2011-5022, it is essential to upgrade Pligg CMS to a version that has addressed this SQL injection vulnerability.
3
What software is affected by CVE-2011-5022?
CVE-2011-5022 specifically affects Pligg CMS version 1.1.2.
4
What is the method of attack for CVE-2011-5022?
The method of attack for CVE-2011-5022 involves exploiting the search.php script through the status parameter to execute arbitrary SQL commands.
5
Who can exploit CVE-2011-5022?
CVE-2011-5022 can be exploited by remote attackers with no authentication required to execute the SQL injection attack.