First published: Wed Jan 09 2008(Updated: )
SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_temp_id parameter in a cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealFlex RealWin | =1.0_10005_beta_release_1 | |
RealFlex RealWin | <=0.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0157 is considered a high-severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2008-0157, update FlexBB to version 1.0_10005_beta_release_1 or later, or implement proper input sanitization for the flexbb_temp_id parameter.
CVE-2008-0157 can facilitate SQL injection attacks, allowing attackers to manipulate the database and potentially gain unauthorized access to sensitive data.
CVE-2008-0157 affects FlexBB versions 0.6.3 and earlier.
Yes, CVE-2008-0157 is exploitable by remote attackers without requiring authentication.