First published: Thu Jan 10 2008(Updated: )
SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrary SQL commands via the Client-Ip parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Runcms Runcms | =1.5.3 | |
Runcms Runcms | =1.6.1 | |
Runcms Runcms | =1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-0224 is considered high due to the potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2008-0224, upgrade to a patched version of RunCMS that addresses SQL injection vulnerabilities.
CVE-2008-0224 affects RunCMS versions 1.5.3 and 1.6.1, as well as earlier versions.
An SQL injection vulnerability like CVE-2008-0224 allows attackers to manipulate SQL queries through unsanitized input, potentially compromising database security.
Yes, CVE-2008-0224 could lead to data loss, unauthorized disclosure of information, or loss of database integrity due to the execution of arbitrary SQL commands.