CVE-2008-1715: SQL Injection
Published Apr 9, 2008
·Updated
SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magicquotesgpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter.
Affected Software
1 affected component
AuraCMS AuraCMS<=2.2.1
Event History
Apr 9, 2008
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
Can I prevent CVE-2008-1715 through configuration changes?
While configuration changes like enabling magic_quotes_gpc may mitigate some risk, the best approach is upgrading to a patched version.