CVE-2008-1398: SQL Injection
Published Mar 20, 2008
·Updated
SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTPXFORWARDEDFOR environment variable) in an HTTP header.
Affected Software
3 affected components
AuraCMS AuraCMS=2.0
AuraCMS AuraCMS=2.2.1
AuraCMS AuraCMS=2.1
Event History
Mar 20, 2008
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1398?
CVE-2008-1398 is considered a critical vulnerability due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2008-1398?
To fix CVE-2008-1398, ensure that input from the X-Forwarded-For header is properly sanitized or validated.
3
Which versions of AuraCMS are affected by CVE-2008-1398?
CVE-2008-1398 affects AuraCMS versions 2.0 through 2.2.1.
4
What type of attacks can CVE-2008-1398 facilitate?
CVE-2008-1398 can facilitate arbitrary SQL command execution by remote attackers.
5
Is there any known exploit for CVE-2008-1398?
Yes, there are known exploits for CVE-2008-1398 that demonstrate how attackers can leverage the vulnerability.