CVE-2008-2460: SQL Injection
Published May 27, 2008
·Updated
SQL injection vulnerability in faq.php in vBulletin 3.7.0 Gold allows remote attackers to execute arbitrary SQL commands via the q parameter in a search action.
Affected Software
1 affected component
vBulletin vBulletin=3.7.0-gold
Event History
May 27, 2008
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2460?
The severity of CVE-2008-2460 is classified as high due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2008-2460?
To fix CVE-2008-2460, users should upgrade to a newer version of vBulletin, specifically beyond 3.7.0 Gold.
3
What software is affected by CVE-2008-2460?
CVE-2008-2460 specifically affects vBulletin version 3.7.0 Gold.
4
What type of vulnerability is CVE-2008-2460?
CVE-2008-2460 is classified as an SQL injection vulnerability.
5
Can CVE-2008-2460 lead to data breaches?
Yes, CVE-2008-2460 can lead to data breaches as it allows attackers to execute arbitrary SQL commands against the database.