CVE-2008-0490: SQL Injection
Published Jan 30, 2008
·Updated
SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
Affected Software
1 affected component
WordPress Wp Cal Plugin=0.3
Event History
Jan 30, 2008
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0490?
CVE-2008-0490 is classified as a moderate severity SQL injection vulnerability.
2
How do I fix CVE-2008-0490?
To fix CVE-2008-0490, update the WP-Cal plugin to the latest version that addresses this vulnerability.
3
What type of attack can be executed through CVE-2008-0490?
CVE-2008-0490 allows attackers to execute arbitrary SQL commands, potentially compromising the database.
4
Which versions of the WP-Cal plugin are affected by CVE-2008-0490?
CVE-2008-0490 specifically affects version 0.3 of the WP-Cal plugin for WordPress.
5
Can CVE-2008-0490 lead to data loss?
Yes, exploitation of CVE-2008-0490 could result in unauthorized access to or modification of database contents, leading to data loss.