CVE-2008-0677: SQL Injection
Published Feb 12, 2008
·Updated
SQL injection vulnerability in blog.php in A-Blog 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a news action.
Affected Software
1 affected component
A-Blog A-Blog=2
Event History
Feb 12, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0677?
CVE-2008-0677 is classified as a medium severity vulnerability due to its potential for arbitrary SQL command execution.
2
How do I fix CVE-2008-0677?
To fix CVE-2008-0677, validate and sanitize the id parameter to prevent SQL injection attacks.
3
Which versions of A-Blog are affected by CVE-2008-0677?
CVE-2008-0677 affects A-Blog version 2.
4
What type of vulnerability is CVE-2008-0677?
CVE-2008-0677 is an SQL injection vulnerability.
5
Can CVE-2008-0677 be exploited remotely?
Yes, CVE-2008-0677 can be exploited remotely by attackers to execute arbitrary SQL commands.