CVE-2008-1462: SQL Injection
Published Mar 24, 2008
·Updated
SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle action.
Affected Software
1 affected component
Runcms RunCMS
Event History
Mar 24, 2008
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1462?
CVE-2008-1462 has a medium severity rating due to its potential for SQL injection attacks.
2
How do I fix CVE-2008-1462?
To fix CVE-2008-1462, update to the latest version of RunCMS that addresses this SQL injection vulnerability.
3
What systems are affected by CVE-2008-1462?
CVE-2008-1462 affects all versions of RunCMS that implement the sections module.
4
Can CVE-2008-1462 lead to data compromise?
Yes, CVE-2008-1462 allows remote attackers to execute arbitrary SQL commands, potentially compromising sensitive data.
5
How can I determine if my application is vulnerable to CVE-2008-1462?
You can determine vulnerability to CVE-2008-1462 by testing the artid parameter in the viewarticle action for SQL injection weaknesses.