CVE-2008-1646: SQL Injection
Published Apr 2, 2008
·Updated
SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the dlid parameter.
Affected Software
2 affected components
WordPress Wp Download=1.2
Arnos Toolbox Wp-download=1.2
Event History
Apr 2, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1646?
CVE-2008-1646 is considered a critical SQL injection vulnerability due to its potential impact on database integrity.
2
How do I fix CVE-2008-1646?
To fix CVE-2008-1646, it is recommended to update the WP-Download plugin to a version that addresses this vulnerability.
3
Who is affected by CVE-2008-1646?
CVE-2008-1646 affects users of the WP-Download 1.2 plugin for WordPress and Arnos Toolbox.
4
What types of attacks can exploit CVE-2008-1646?
CVE-2008-1646 can be exploited to execute arbitrary SQL commands in the database.
5
When was CVE-2008-1646 disclosed?
CVE-2008-1646 was disclosed in 2008, making awareness of its implications important for legacy system security.