HIGH · 7.5

CVE-2009-2451

Multiple SQL injection vulnerabilities in index.php in MIM:InfiniX 1.2.003 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year paramet...

Vulnerability Description

Multiple SQL injection vulnerabilities in index.php in MIM:InfiniX 1.2.003 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters in a calendar action, or (3) a search term in the search form.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Mim.InfinixInfinix<= 1.2.003

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-2451?

CVE-2009-2451 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple SQL injection vulnerabilities in index.php in MIM:InfiniX 1.2.003 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year paramet...

How severe is CVE-2009-2451?

CVE-2009-2451 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-2451?

Check the references section above for vendor advisories and patch information. Affected products include: Mim.Infinix Infinix.