First published: Fri Apr 18 2008(Updated: )
Multiple SQL injection vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to events.asp, the (2) UserName parameter to getpassword.asp, and possibly an unspecified parameter to (3) option_Update.asp in an edit action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invision Community | <=2.4 | |
Invision Community | =1.0 | |
Invision Community | =1.1 | |
Invision Community | =2.1 | |
Invision Community | =2.2 | |
Invision Community | =2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1895 contains multiple SQL injection vulnerabilities that affect the ID, UserName, and possibly other parameters in several ASP pages.
CVE-2008-1895 affects Carbon Communities versions 2.4 and earlier.
By exploiting CVE-2008-1895, a remote attacker could execute arbitrary SQL commands against the database.
To protect against CVE-2008-1895, ensure you update to the latest version of Carbon Communities and implement proper input validation.
Yes, users should upgrade to a version of Carbon Communities later than 2.4 to mitigate the vulnerabilities outlined in CVE-2008-1895.