CVE-2008-1308: SQL Injection
Published Mar 12, 2008
·Updated
SQL injection vulnerability in the Sudirman Angriawan NukeC30 3.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the idcatg parameter in a ViewCatg action to modules.php.
Affected Software
2 affected components
Phpnuke Php-nuke
Sudirman Angriawan NukeC30=3.0
Event History
Mar 12, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
05:44 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-1308?
CVE-2008-1308 is classified as a critical SQL injection vulnerability.
2
How do I fix CVE-2008-1308?
To fix CVE-2008-1308, it is recommended to update to a secure version of the Sudirman Angriawan NukeC30 module.
3
What are the potential impacts of CVE-2008-1308?
The impacts of CVE-2008-1308 include unauthorized access to the database and execution of arbitrary SQL commands.
4
Who is affected by CVE-2008-1308?
Users of the Sudirman Angriawan NukeC30 3.0 module for PHP-Nuke are directly affected by CVE-2008-1308.
5
How can attackers exploit CVE-2008-1308?
Attackers can exploit CVE-2008-1308 by sending crafted requests that include malicious SQL code in the id_catg parameter.