CVE-2009-4698

N/A Unknown
Published: March 15, 2010 Modified: April 29, 2026
View on NVD

Description

Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso.php and (2) imprimir.php, and the (3) cod_categoria parameter to categoria.php.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/56593
Source: cve@mitre.org
http://osvdb.org/56595
Source: cve@mitre.org
http://secunia.com/advisories/35966
Source: cve@mitre.org
Vendor Advisory
http://www.osvdb.org/56594
Source: cve@mitre.org
http://www.securityfocus.com/bid/35820
Source: cve@mitre.org
Exploit
http://osvdb.org/56593
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/56595
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/35966
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.exploit-db.com/exploits/9249
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.exploit-db.com/exploits/9261
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/56594
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/35820
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/51985
Source: af854a3a-2127-422b-91ae-364da2661108

16 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
1.7%
74th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

xoops alexandre_amaral