CVE-2008-0138: SQL Injection
Published Jan 8, 2008
·Updated
PHP remote file inclusion vulnerability in xoopsgallery/initbasic.php in the modgallery module for XOOPS, when registerglobals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the GALLERYBASEDIR parameter.
Affected Software
1 affected component
Xoops Xoopsgallery Module=1.3.3_9
Event History
Jan 8, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0138?
CVE-2008-0138 is considered a high severity vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2008-0138?
To fix CVE-2008-0138, upgrade to a patched version of the mod_gallery module for XOOPS that addresses this vulnerability.
3
What systems are affected by CVE-2008-0138?
CVE-2008-0138 affects the mod_gallery module version 1.3.3_9 for XOOPS.
4
What type of vulnerability is CVE-2008-0138?
CVE-2008-0138 is classified as a remote file inclusion vulnerability.
5
Can CVE-2008-0138 be exploited if register_globals is enabled?
CVE-2008-0138's exploitability is primarily targeted when register_globals is disabled, though it can still pose risks.