CVE-2013-4789: SQL Injection
Published Aug 9, 2013
·Updated
SQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary SQL commands via the "c" parameter to index.php.
Affected Software
14 affected components
Cotonti Cotonti Siena<=0.9.13
Cotonti Cotonti Siena=0.9.0
Cotonti Cotonti Siena=0.9.1
Cotonti Cotonti Siena=0.9.2
Cotonti Cotonti Siena=0.9.3
Cotonti Cotonti Siena=0.9.4
Cotonti Cotonti Siena=0.9.5
Cotonti Cotonti Siena=0.9.6
Cotonti Cotonti Siena=0.9.7
Cotonti Cotonti Siena=0.9.8
Cotonti Cotonti Siena=0.9.9
Cotonti Cotonti Siena=0.9.10
Cotonti Cotonti Siena=0.9.11
Cotonti Cotonti Siena=0.9.12
Remediation
Event History
Aug 9, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4789?
The severity of CVE-2013-4789 is classified as high due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2013-4789?
To fix CVE-2013-4789, upgrade to Cotonti version 0.9.14 or later, which includes the patched code.
3
Which versions of Cotonti are affected by CVE-2013-4789?
CVE-2013-4789 affects all Cotonti versions prior to 0.9.14, including versions 0.9.0 to 0.9.13.
4
What kind of attacks can be executed due to CVE-2013-4789?
Due to CVE-2013-4789, an attacker can perform SQL injection attacks, potentially leading to data breaches and unauthorized access.
5
Is CVE-2013-4789 publicly known?
Yes, CVE-2013-4789 is a publicly known vulnerability that has been documented in several security advisories.