CVE-2008-0835: SQL Injection
Published Feb 20, 2008
·Updated
SQL injection vulnerability in indexen.php in Simple CMS 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the area parameter.
Affected Software
1 affected component
Simple CMS Simple CMS=1.0.3
Event History
Feb 20, 2008
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0835?
CVE-2008-0835 is considered to be of high severity due to its potential for remote code execution via SQL injection.
2
How do I fix CVE-2008-0835?
To fix CVE-2008-0835, update Simple CMS to version 1.0.4 or later and implement input validation for the 'area' parameter.
3
What systems are affected by CVE-2008-0835?
CVE-2008-0835 affects Simple CMS version 1.0.3 and earlier.
4
What type of vulnerability is CVE-2008-0835?
CVE-2008-0835 is a SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
5
Can CVE-2008-0835 lead to data theft?
Yes, CVE-2008-0835 can lead to data theft, unauthorized access, and manipulation of the database.