Interspire · Interspire Activekb · CVE-2007-5131
**Name of the Vulnerable Software and Affected Versions**
Interspire ActiveKB NX versions 2.x
Interspire ActiveKB version 1.5
**Description**
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `catId` parameter in a 'browse' action.
**Recommendations**
For Interspire ActiveKB NX versions 2.x, avoid using the `catId` parameter in the affected API endpoint until the issue is resolved.
For Interspire ActiveKB version 1.5, avoid using the `catId` parameter in the affected API endpoint until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.