CVE-2008-2381: SQL Injection
Published Jan 2, 2009
·Updated
SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.
Affected Software
2 affected components
GForge=4.5
GForge=4.6
Event History
Jan 2, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2381?
CVE-2008-2381 is classified as a high-severity SQL injection vulnerability that can lead to arbitrary SQL command execution.
2
How do I fix CVE-2008-2381?
To fix CVE-2008-2381, update GForge to version 4.7 or later, or apply security patches that address the SQL injection flaw.
3
What software versions are affected by CVE-2008-2381?
The affected software versions for CVE-2008-2381 are GForge 4.5 and 4.6.
4
Who is vulnerable to CVE-2008-2381?
Any user or organization using GForge versions 4.5 or 4.6 is vulnerable to CVE-2008-2381.
5
What type of vulnerability is CVE-2008-2381?
CVE-2008-2381 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.