CVE-2017-11174: SQL Injection
Published Jul 12, 2017
·Updated
In install/pagedbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page, related to use of GBK in CHARACTER SET and COLLATE clauses.
Affected Software
1 affected component
Xoops Xoops=2.5.8.1
Event History
Jul 12, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11174?
CVE-2017-11174 has a medium severity rating due to its potential for SQL Injection vulnerabilities.
2
How do I fix CVE-2017-11174?
To fix CVE-2017-11174, upgrade to a patched version of XOOPS beyond 2.5.8.1.
3
What types of attacks can CVE-2017-11174 facilitate?
CVE-2017-11174 can facilitate SQL Injection attacks, allowing an attacker to manipulate database queries.
4
Which software versions are affected by CVE-2017-11174?
The only affected version by CVE-2017-11174 is XOOPS 2.5.8.1.
5
What components are involved in CVE-2017-11174?
CVE-2017-11174 specifically involves the install/page_dbsettings.php file in the XOOPS Core distribution.