CVE-2018-19462: SQL Injection
Published Jun 7, 2019
·Updated
admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php.
Affected Software
1 affected component
Phome Empirecms<=7.5.0
Event History
Jun 7, 2019
CVE Published
via MITRE·04:44 PM
Data Sourced
via MITRE·04:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19462?
CVE-2018-19462 has a medium severity rating due to the potential for remote code execution through SQL injection.
2
How do I fix CVE-2018-19462?
To fix CVE-2018-19462, upgrade your EmpireCMS to the latest version above 7.5 to avoid SQL injection vulnerabilities.
3
What type of vulnerability is CVE-2018-19462?
CVE-2018-19462 is an SQL injection vulnerability that allows attackers to execute arbitrary PHP code.
4
Which versions of EmpireCMS are affected by CVE-2018-19462?
EmpireCMS versions up to and including 7.5 are affected by CVE-2018-19462.
5
What can attackers achieve by exploiting CVE-2018-19462?
By exploiting CVE-2018-19462, attackers can execute arbitrary PHP code on the server, potentially leading to full system compromise.