First published: Tue May 27 2008(Updated: )
SQL injection vulnerability in faq.php in vBulletin 3.7.0 Gold allows remote attackers to execute arbitrary SQL commands via the q parameter in a search action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
vBulletin | =3.7.0-gold |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-2460 is classified as high due to the potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2008-2460, users should upgrade to a newer version of vBulletin, specifically beyond 3.7.0 Gold.
CVE-2008-2460 specifically affects vBulletin version 3.7.0 Gold.
CVE-2008-2460 is classified as an SQL injection vulnerability.
Yes, CVE-2008-2460 can lead to data breaches as it allows attackers to execute arbitrary SQL commands against the database.