CVE-2008-0719: SQL Injection
SQL injection vulnerability in customertestimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote attackers to execute arbitrary SQL commands via the testimonialid parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0719?
CVE-2008-0719 is classified as a high severity vulnerability due to its potential for arbitrary SQL command execution.
How do I fix CVE-2008-0719?
To fix CVE-2008-0719, you should update the Customer Testimonials Addon to the latest version or apply appropriate input validation to sanitize the testimonial_id parameter.
What systems are affected by CVE-2008-0719?
CVE-2008-0719 affects versions 3 and 3.1 of the Customer Testimonials Addon for osCommerce Online Merchant 2.2.
What type of vulnerability is CVE-2008-0719?
CVE-2008-0719 is an SQL injection vulnerability, allowing attackers to execute arbitrary SQL commands.
Who can exploit CVE-2008-0719?
Remote attackers can exploit CVE-2008-0719 by crafting requests that manipulate the testimonial_id parameter.