CVE-2008-1551: SQL Injection
Published Mar 31, 2008
·Updated
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter.
Affected Software
2 affected components
Runcms Photo Module=3.02
Runcms RunCMS
Event History
Mar 31, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1551?
CVE-2008-1551 is categorized as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2008-1551?
To fix CVE-2008-1551, ensure proper sanitization of user inputs, particularly the cid parameter in viewcat.php.
3
What software is affected by CVE-2008-1551?
CVE-2008-1551 affects the Photo 3.02 module for RunCMS.
4
Can CVE-2008-1551 lead to data loss?
Yes, CVE-2008-1551 can allow remote attackers to execute arbitrary SQL commands, potentially leading to data loss.
5
Is CVE-2008-1551 exploitable remotely?
Yes, CVE-2008-1551 can be exploited by remote attackers.