CVE-2008-3366: SQL Injection
Published Jul 30, 2008
·Updated
SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2008-1774.
Affected Software
2 affected components
Pligg Pligg CMS=9.9.0-beta
Pligg Pligg CMS=9.9.0
Event History
Jul 30, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3366?
CVE-2008-3366 is considered a high severity vulnerability due to the potential for arbitrary SQL command execution.
2
How do I fix CVE-2008-3366?
To mitigate CVE-2008-3366, users should upgrade to a patched version of Pligg CMS that addresses this SQL injection issue.
3
What software is affected by CVE-2008-3366?
CVE-2008-3366 affects Pligg CMS version 9.9.0, both the beta and stable releases.
4
Can CVE-2008-3366 be exploited remotely?
Yes, CVE-2008-3366 can be exploited remotely by attackers to execute malicious SQL commands.
5
What is the impact of CVE-2008-3366 on web applications?
The impact of CVE-2008-3366 on web applications can include unauthorized access to the database and potential data breaches.