CVE-2008-0874: SQL Injection
Published Feb 21, 2008
·Updated
SQL injection vulnerability in index.php in the eEmpregos module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.
Affected Software
1 affected component
Xoops eEmpregos module
Event History
Feb 21, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0874?
CVE-2008-0874 is considered to have a medium severity due to its potential to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2008-0874?
To fix CVE-2008-0874, assess your current version of the eEmpregos module and update to the latest patched version that addresses the SQL injection vulnerability.
3
What is affected by CVE-2008-0874?
CVE-2008-0874 affects the eEmpregos module for XOOPS, specifically the index.php file where the cid parameter can be exploited.
4
Can CVE-2008-0874 be exploited remotely?
Yes, CVE-2008-0874 allows remote attackers to exploit the SQL injection vulnerability.
5
What type of vulnerability is CVE-2008-0874?
CVE-2008-0874 is classified as an SQL injection vulnerability.