CVE-2015-6943: SQL Injection
Published Sep 15, 2015
·Updated
SQL injection vulnerability in the serendipitycheckCommentToken function in include/functionscomments.inc.php in Serendipity before 2.0.2, when "Use Tokens for Comment Moderation" is enabled, allows remote administrators to execute arbitrary SQL commands via the serendipity[id] parameter to serendipityadmin.php.
Affected Software
1 affected component
S9Y serendipity<=2.0.1
Remediation
Event History
Sep 15, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6943?
CVE-2015-6943 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2015-6943?
To mitigate CVE-2015-6943, upgrade to Serendipity version 2.0.2 or later.
3
What systems are affected by CVE-2015-6943?
CVE-2015-6943 affects Serendipity versions prior to 2.0.2 when 'Use Tokens for Comment Moderation' is enabled.
4
What type of vulnerability is CVE-2015-6943?
CVE-2015-6943 is an SQL injection vulnerability.
5
Who can exploit CVE-2015-6943?
CVE-2015-6943 can potentially be exploited by remote administrators who can send crafted requests.