CVE-2008-1406: SQL Injection
Published Mar 20, 2008
·Updated
SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the lid parameter in an ImprAnn action.
Affected Software
1 affected component
eXV2 eXV2=1.8
Event History
Mar 20, 2008
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1406?
CVE-2008-1406 is considered a high severity vulnerability due to the potential for remote SQL injection attacks.
2
How do I fix CVE-2008-1406?
To fix CVE-2008-1406, validate and sanitize user inputs in the lid parameter before processing SQL commands.
3
What software is affected by CVE-2008-1406?
CVE-2008-1406 affects MyAnnonces version 1.8 for the eXV2 system.
4
What type of vulnerabilities does CVE-2008-1406 represent?
CVE-2008-1406 represents a SQL injection vulnerability that allows attackers to execute arbitrary SQL code.
5
How can I mitigate CVE-2008-1406?
Mitigation for CVE-2008-1406 includes implementing input validation, using prepared statements, and applying security patches.