CVE-2008-3092: SQL Injection
SQL injection vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3092?
CVE-2008-3092 is classified as a critical vulnerability due to its potential to allow remote authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2008-3092?
To fix CVE-2008-3092, upgrade the Taxonomy Autotagger module to version 5.x-1.8 or later.
Who is affected by CVE-2008-3092?
CVE-2008-3092 affects remote authenticated users with create or edit post permissions on Drupal installations using the vulnerable Taxonomy Autotagger module.
What types of attacks can exploit CVE-2008-3092?
CVE-2008-3092 can be exploited to perform SQL injection attacks, allowing attackers to manipulate the database.
Is CVE-2008-3092 still relevant today?
While CVE-2008-3092 is an older vulnerability, systems still running affected versions of the Taxonomy Autotagger module may still be at risk if not updated.