CVE-2008-2850: SQL Injection
Published Jun 25, 2008
·Updated
SQL injection vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified cookies, related to improper use of the Drupal database API.
Affected Software
5 affected components
Drupal TrailScout module=5.x_1.0
Drupal TrailScout module=5.x
Drupal TrailScout module=5.x_1.3
Drupal TrailScout module=5.x_1.2
Drupal TrailScout module=5.x_1.1
Remediation
Patch Available
Event History
Jun 25, 2008
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2850?
CVE-2008-2850 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2008-2850?
To fix CVE-2008-2850, upgrade the TrailScout module to version 5.x-1.4 or later.
3
What versions of the TrailScout module are affected by CVE-2008-2850?
CVE-2008-2850 affects TrailScout module versions 5.x before 5.x-1.4.
4
What type of vulnerability is CVE-2008-2850?
CVE-2008-2850 is an SQL injection vulnerability.
5
Can CVE-2008-2850 be exploited through cookies?
Yes, CVE-2008-2850 can be exploited via unspecified cookies due to improper use of the Drupal database API.