CWE
89
Advisory Published
Updated

CVE-2016-9481: SQL Injection

First published: Tue Nov 29 2016(Updated: )

In framework/modules/core/controllers/expCommentController.php of Exponent CMS 2.4.0, content_id input is passed into showComments. The method showComments is defined in the expCommentControllercontroller with the parameter '$this->params['content_id']' used directly in SQL. Impact is a SQL injection.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Exponentcms Exponent Cms=2.4.0

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2016-9481?

    CVE-2016-9481 is classified as a critical vulnerability due to the potential for SQL injection.

  • What impact does CVE-2016-9481 have on Exponent CMS?

    CVE-2016-9481 allows an attacker to perform SQL injection, potentially compromising the database.

  • How do I fix CVE-2016-9481?

    To fix CVE-2016-9481, upgrade to a patched version of Exponent CMS that addresses the SQL injection vulnerability.

  • Which versions of Exponent CMS are affected by CVE-2016-9481?

    CVE-2016-9481 affects Exponent CMS version 2.4.0.

  • Is there a way to detect if CVE-2016-9481 has been exploited?

    To detect exploitation of CVE-2016-9481, check the application logs for unusual SQL queries or unauthorized access patterns.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203