CVE-2008-0714: SQL Injection
Published Feb 12, 2008
·Updated
SQL injection vulnerability in users.php in Mihalism Multi Host allows remote attackers to execute arbitrary SQL commands via the username parameter in a lostpasswordgo action.
Affected Software
1 affected component
Mihalism Multi Host=3.0
Event History
Feb 12, 2008
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0714?
CVE-2008-0714 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2008-0714?
To fix CVE-2008-0714, validate and sanitize the username parameter to prevent SQL injection.
3
Who is affected by CVE-2008-0714?
CVE-2008-0714 affects users of Mihalism Multi Host version 3.0.
4
What type of attacks can CVE-2008-0714 facilitate?
CVE-2008-0714 can facilitate arbitrary SQL command execution by remote attackers.
5
Is CVE-2008-0714 still a threat today?
While CVE-2008-0714 is an older vulnerability, it remains a threat if the affected software is still in use without proper mitigation.