CVE-2008-2191: SQL Injection
Published May 14, 2008
·Updated
SQL injection vulnerability in the pnEncyclopedia module 0.2.0 and earlier for PostNuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a displayterm action to index.php.
Affected Software
1 affected component
Postnuke Software Foundation Pnencyclopedia<=0.2.0
Event History
May 14, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2191?
CVE-2008-2191 is considered a high severity vulnerability due to its SQL injection capability.
2
How do I fix CVE-2008-2191?
To fix CVE-2008-2191, upgrade the pnEncyclopedia module to a version later than 0.2.0.
3
Who is affected by CVE-2008-2191?
CVE-2008-2191 affects users of the pnEncyclopedia module in PostNuke version 0.2.0 and earlier.
4
What type of vulnerability is CVE-2008-2191?
CVE-2008-2191 is classified as an SQL injection vulnerability.
5
Can CVE-2008-2191 allow attackers to compromise my database?
Yes, CVE-2008-2191 can allow remote attackers to execute arbitrary SQL commands, potentially compromising your database.