First published: Fri Jul 11 2008(Updated: )
SQL injection vulnerability in the 4ndvddb 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a show_dvd action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Warpspeed 4ndvddb | =0.91 | |
Phpnuke 4ndvddb | =0.91 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3151 is classified as a high severity SQL injection vulnerability.
To fix CVE-2008-3151, sanitize and validate user inputs to the id parameter in the show_dvd action.
CVE-2008-3151 affects version 0.91 of the 4ndvddb module for both Warpspeed and PHP-Nuke.
CVE-2008-3151 allows remote attackers to execute arbitrary SQL commands.
Yes, CVE-2008-3151 can be exploited by remote attackers without needing authentication.