CVE-2016-4337: SQL Injection
Published Apr 12, 2017
·Updated
SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recoverlogin action.
Affected Software
1 affected component
Ktools Photostore<=4.7.4
Event History
Apr 12, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4337?
CVE-2016-4337 is classified as a high severity vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2016-4337?
To fix CVE-2016-4337, you should upgrade Ktools.net Photostore to version 4.7.5 or later.
3
What is the impact of CVE-2016-4337?
The impact of CVE-2016-4337 includes unauthorized access to the database, which can lead to data leakage or manipulation.
4
Which versions of Ktools.net Photostore are affected by CVE-2016-4337?
Ktools.net Photostore versions prior to 4.7.5 are affected by CVE-2016-4337.
5
What specific file is vulnerable in CVE-2016-4337?
The vulnerable file in CVE-2016-4337 is mgr.login.php.