CVE-2018-19415: SQL Injection
Published Jan 3, 2019
·Updated
Multiple SQL injection vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to joingroup.php or (2) commentid parameter to story.php.
Affected Software
1 affected component
Plikli Plikli CMS=4.0.0
Event History
Jan 3, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19415?
CVE-2018-19415 is rated as a high severity vulnerability due to its potential for remote SQL command execution.
2
How do I fix CVE-2018-19415?
To mitigate CVE-2018-19415, it is recommended to upgrade Plikli CMS to a version that has patched these SQL injection vulnerabilities.
3
What are the vulnerable parameters in CVE-2018-19415?
CVE-2018-19415 is vulnerable through the 'id' parameter in join_group.php and the 'comment_id' parameter in story.php.
4
Who is affected by CVE-2018-19415?
Users running Plikli CMS version 4.0.0 are affected by CVE-2018-19415.
5
Can CVE-2018-19415 be exploited remotely?
Yes, CVE-2018-19415 can be exploited remotely by attackers to execute arbitrary SQL commands.