First published: Mon Jul 07 2008(Updated: )
SQL injection vulnerability in the News Calendar (newscalendar) extension 1.0.7 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Typo3 News Calendar Extension | <=1.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-3044 is rated as critical due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2008-3044, upgrade the News Calendar extension to version 1.0.8 or later.
CVE-2008-3044 affects the News Calendar extension for TYPO3 version 1.0.7 and earlier.
CVE-2008-3044 is exploited through SQL injection, allowing attackers to send specially crafted requests to execute arbitrary SQL commands.
There are no documented workarounds for CVE-2008-3044; the recommended action is to update the affected extension.