CVE-2008-2012: SQL Injection
Published Apr 30, 2008
·Updated
SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the eid parameter in an event action.
Affected Software
1 affected component
Postnuke Software Foundation Postschedule=1.0
Event History
Apr 30, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2012?
The severity of CVE-2008-2012 is considered high due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2008-2012?
To fix CVE-2008-2012, it is recommended to update to the latest version of the PostSchedule module or apply proper input validation to sanitize the eid parameter.
3
What systems are affected by CVE-2008-2012?
CVE-2008-2012 affects version 1.0 of the PostSchedule module for PostNuke.
4
What type of vulnerability is CVE-2008-2012?
CVE-2008-2012 is categorized as an SQL injection vulnerability.
5
Can CVE-2008-2012 be exploited without authentication?
Yes, CVE-2008-2012 can be exploited by remote attackers without requiring authentication.