First published: Thu Mar 30 2017(Updated: )
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
E-xoops | =2.5.7.2 | |
E-xoops | =2.5.7.3 | |
E-xoops | =2.5.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7290 is considered a high severity vulnerability due to its potential for remote SQL injection attacks.
To fix CVE-2017-7290, upgrade to XOOPS version 2.5.8.1 or later.
CVE-2017-7290 affects XOOPS versions 2.5.7.2 through 2.5.8.1.
CVE-2017-7290 is an SQL injection vulnerability.
Yes, CVE-2017-7290 can be exploited remotely by authenticated administrators.