SQL Injection Vulnerability in XOOPS Core by XOOPS Foundation
CVE-2017-11174

9.8CRITICAL

Key Information:

Vendor

Xoops

Status
Vendor
CVE Published:
12 July 2017

What is CVE-2017-11174?

A vulnerability in the XOOPS Core distribution (version 2.5.8.1) allows attackers to execute SQL Injection attacks through unfiltered user input in database settings. Specifically, the flaw arises in the install/page_dbsettings.php file, where manipulation of CREATE and ALTER SQL queries could expose sensitive information or compromise the database. This security risk underlines the importance of validating and sanitizing user input to maintain database integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.