First published: Mon Jul 07 2008(Updated: )
SQL injection vulnerability in the Branchenbuch (aka Yellow Pages o (mh_branchenbuch) extension 0.8.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Typo3 Branchenbuch Extension | <=0.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-3054 is considered high due to the potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2008-3054, upgrade the Branchenbuch extension to version 0.8.2 or later.
CVE-2008-3054 affects the Branchenbuch extension version 0.8.1 and earlier for TYPO3.
Yes, CVE-2008-3054 can lead to data breaches due to the exploitation of the SQL injection vulnerability by attackers.
While specific exploit scenarios are not detailed, any input fields that interact with the SQL database are potential attack vectors for CVE-2008-3054.