First published: Wed Mar 12 2008(Updated: )
SQL injection vulnerability in the Johannes Hass gaestebuch 2.2 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action to modules.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Johannes Hass Gaestebuch Module | =2.2 | |
PHP-Nuke |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1314 is considered a high severity vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2008-1314, update to a newer version of the Johannes Hass Gaestebuch module that addresses this SQL injection vulnerability.
CVE-2008-1314 specifically affects the Johannes Hass Gaestebuch module version 2.2 for PHP-Nuke.
CVE-2008-1314 exploits SQL injection through the id parameter in an edit action to modules.php, allowing execution of malicious SQL commands.
Attackers exploiting CVE-2008-1314 can manipulate the database, potentially leading to unauthorized data access or modification.