CVE-2012-6507: SQL Injection
Published Jan 24, 2013
·Updated
Multiple SQL injection vulnerabilities in admin.php in ChurchCMS 0.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pass parameters in a login action.
Affected Software
1 affected component
Jason Sexauer Churchcms=0.0.1
Event History
Jan 24, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6507?
CVE-2012-6507 is considered a critical vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2012-6507?
To fix CVE-2012-6507, upgrade to a patched version of ChurchCMS that addresses the SQL injection vulnerabilities.
3
What are the impacted components in CVE-2012-6507?
CVE-2012-6507 affects the admin.php file in ChurchCMS version 0.0.1.
4
What actions can attackers perform through CVE-2012-6507?
Attackers can exploit CVE-2012-6507 to manipulate SQL queries and gain unauthorized access to the database.
5
Is CVE-2012-6507 easy to exploit?
Yes, CVE-2012-6507 is relatively easy to exploit if proper security measures are not implemented.