PT-2010-1396 · Maxdev · Mforum

Published

2010-01-06

·

Updated

2024-02-14

·

CVE-2009-4577

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MDForum module versions 2.x through 2.07 for MAXdev MDPro
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the c parameter in the "index.php" endpoint.
Recommendations For MDForum module versions 2.x through 2.07, consider restricting access to the c parameter in the "index.php" endpoint until a patch is available.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2009-4577

Affected Products

Mforum