CVE-2017-7290: SQL Injection
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
XOOPSto a version that resolves this vulnerability.Fixed in 2.5.8.1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7290?
CVE-2017-7290 is considered a high severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2017-7290?
To fix CVE-2017-7290, upgrade to XOOPS version 2.5.8.1 or later.
Who is affected by CVE-2017-7290?
CVE-2017-7290 affects XOOPS versions 2.5.7.2 through 2.5.8.1.
What type of vulnerability is CVE-2017-7290?
CVE-2017-7290 is an SQL injection vulnerability.
Can CVE-2017-7290 be exploited remotely?
Yes, CVE-2017-7290 can be exploited remotely by authenticated administrators.