First published: Mon Mar 17 2008(Updated: )
SQL injection vulnerability in the Tutorials 2.1b module for XOOPS allows remote attackers to execute arbitrary SQL commands via the tid parameter to printpage.php, which is accessible directly or through a printpage action to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xoops Tutoriais Module | =2.1b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1351 is classified as a medium severity vulnerability due to its potential to allow SQL injection attacks.
To fix CVE-2008-1351, update the Tutorials module for XOOPS to a version that patches the SQL injection vulnerability.
CVE-2008-1351 can be exploited by remote attackers to execute arbitrary SQL commands against the affected application.
CVE-2008-1351 specifically affects the Tutorials module version 2.1b for XOOPS.
CVE-2008-1351 may lead to unauthorized data access and manipulation, compromising the integrity of the database.