CVE-2008-0421: SQL Injection
Published Jan 23, 2008
·Updated
SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in a rate command.
Affected Software
1 affected component
Invision Power Services Invision Gallery<=2.0.7
Event History
Jan 23, 2008
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0421?
CVE-2008-0421 is classified as a high-severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2008-0421?
To fix CVE-2008-0421, you should update Invision Gallery to version 2.0.8 or later, which addresses the SQL injection vulnerability.
3
Which versions of Invision Gallery are affected by CVE-2008-0421?
CVE-2008-0421 affects Invision Gallery versions 2.0.7 and earlier.
4
What type of vulnerability is CVE-2008-0421?
CVE-2008-0421 is an SQL injection vulnerability that can be exploited via the album parameter.
5
Can CVE-2008-0421 lead to data breaches?
Yes, CVE-2008-0421 can lead to data breaches, allowing attackers to manipulate the database and access sensitive information.