CVE-2008-2447: SQL Injection
Published May 27, 2008
·Updated
SQL injection vulnerability in products.php in the Mytipper ZoGo-shop plugin 1.15.5 and 1.16 Beta 13 for e107 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
Affected Software
2 affected components
Mytipper Zogo Shop=1.15.5
Mytipper Zogo Shop=1.16-beta13
Event History
May 27, 2008
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2447?
CVE-2008-2447 is considered to be a high severity SQL injection vulnerability.
2
How do I fix CVE-2008-2447?
To fix CVE-2008-2447, update the Mytipper ZoGo-shop plugin to version 1.16 or later.
3
What versions of Mytipper ZoGo-shop are affected by CVE-2008-2447?
CVE-2008-2447 affects Mytipper ZoGo-shop versions 1.15.5 and 1.16 Beta 13.
4
What is the exploit type for CVE-2008-2447?
CVE-2008-2447 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
5
Which parameter is exploited in CVE-2008-2447?
The 'cat' parameter is exploited in CVE-2008-2447.