First published: Wed May 28 2008(Updated: )
SQL injection vulnerability in the Library for Frontend Plugins (aka sg_zfelib) extension 1.1.512 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified "user input."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Typo3 Sg Zfelib | <=1.1.512 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2489 is rated as a critical severity vulnerability due to its potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2008-2489, update the Library for Frontend Plugins extension to version later than 1.1.512.
Exploiting CVE-2008-2489 can lead to unauthorized access to the database and manipulation of sensitive data.
CVE-2008-2489 affects users of the TYPO3 content management system utilizing the sg_zfelib extension version 1.1.512 and earlier.
CVE-2008-2489 is categorized as an SQL injection vulnerability.