CVE-2008-3151: SQL Injection
Published Jul 11, 2008
·Updated
SQL injection vulnerability in the 4ndvddb 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a showdvd action.
Affected Software
2 affected components
Warpspeed 4ndvddb=0.91
Phpnuke 4ndvddb=0.91
Event History
Jul 11, 2008
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3151?
CVE-2008-3151 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2008-3151?
To fix CVE-2008-3151, sanitize and validate user inputs to the id parameter in the show_dvd action.
3
Which software versions are affected by CVE-2008-3151?
CVE-2008-3151 affects version 0.91 of the 4ndvddb module for both Warpspeed and PHP-Nuke.
4
What type of attack does CVE-2008-3151 allow?
CVE-2008-3151 allows remote attackers to execute arbitrary SQL commands.
5
Is it possible to exploit CVE-2008-3151 without authentication?
Yes, CVE-2008-3151 can be exploited by remote attackers without needing authentication.