CVE-2014-3935: SQL Injection
Published Jun 2, 2014
·Updated
SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commands via the lettre parameter.
Affected Software
1 affected component
Xoops Glossaire Module Xoops=1.0
Event History
Jun 2, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3935?
CVE-2014-3935 has a medium severity rating due to potential unauthorized access to execute arbitrary SQL commands.
2
How do I fix CVE-2014-3935?
To fix CVE-2014-3935, update the Glossaire module to a version that addresses the SQL injection vulnerability.
3
What systems are affected by CVE-2014-3935?
CVE-2014-3935 affects the Glossaire module version 1.0 for XOOPS.
4
Can CVE-2014-3935 be exploited remotely?
Yes, CVE-2014-3935 can be exploited remotely through crafted requests to the affected module.
5
What is the primary vector for the CVE-2014-3935 vulnerability?
The primary vector for CVE-2014-3935 is the 'lettre' parameter in the glossaire-aff.php script.