CVE-2011-5200: SQL Injection
Published Sep 23, 2012
·Updated
Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) list.php, (2) members.php, or (3) book.php.
Affected Software
1 affected component
DedeCMS Dedecms=5.6
Event History
Sep 23, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-5200?
CVE-2011-5200 has a high severity due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2011-5200?
To fix CVE-2011-5200, it is recommended to update DeDeCMS to a version that addresses the SQL injection vulnerabilities.
3
What are the affected versions for CVE-2011-5200?
CVE-2011-5200 specifically affects DeDeCMS version 5.6.
4
What type of vulnerability is CVE-2011-5200?
CVE-2011-5200 is classified as an SQL injection vulnerability.
5
Can CVE-2011-5200 be exploited by unauthenticated attackers?
Yes, CVE-2011-5200 can be exploited by unauthenticated remote attackers.