CVE-2008-1640: SQL Injection
Published Apr 2, 2008
·Updated
SQL injection vulnerability in jgstreffen.php in the JGS-XA JGS-Treffen 2.0.2 and earlier addon for Woltlab Burning Board (wBB) allows remote attackers to execute arbitrary SQL commands via the viewid parameter in an ansicht action.
Affected Software
2 affected components
JGS-XA Jgs Treffen=2.0.1
JGS-XA Jgs Treffen<=2.0.2
Event History
Apr 2, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1640?
CVE-2008-1640 is classified as a medium severity vulnerability, allowing potential unauthorized access to the database.
2
How do I fix CVE-2008-1640?
To fix CVE-2008-1640, upgrade to JGS-Treffen version 2.0.3 or later, which addresses the SQL injection vulnerability.
3
Who is affected by CVE-2008-1640?
Users running JGS-Treffen versions 2.0.1 and earlier are affected by CVE-2008-1640.
4
Can CVE-2008-1640 be exploited remotely?
Yes, CVE-2008-1640 can be exploited remotely by attackers through the view_id parameter.
5
What kind of attacks are possible with CVE-2008-1640?
CVE-2008-1640 allows attackers to execute arbitrary SQL commands, potentially leading to data compromise.