CVE-2008-3038: SQL Injection
Published Jul 7, 2008
·Updated
SQL injection vulnerability in the Address Directory (spdirectory) extension 0.2.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
1 affected component
Typo3 Address Directory<=0.2.10
Event History
Jul 7, 2008
CVE Published
via MITRE·06:20 PM
Data Sourced
via MITRE·06:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3038?
CVE-2008-3038 is classified as a high severity SQL injection vulnerability in the TYPO3 Address Directory extension.
2
How do I fix CVE-2008-3038?
To fix CVE-2008-3038, upgrade to TYPO3 Address Directory extension version 0.2.11 or later to patch the vulnerability.
3
What type of attacks can CVE-2008-3038 facilitate?
CVE-2008-3038 allows remote attackers to execute arbitrary SQL commands that can compromise the database and server.
4
Which versions of TYPO3 are affected by CVE-2008-3038?
CVE-2008-3038 affects TYPO3 Address Directory extension versions 0.2.10 and earlier.
5
Is CVE-2008-3038 still a risk in modern TYPO3 installations?
CVE-2008-3038 poses a risk only in installations running outdated versions of the Address Directory extension.