CVE-2008-3374: SQL Injection
Published Jul 30, 2008
·Updated
SQL injection vulnerability in ajax.php in Gregarius 0.5.4 and earlier allows remote attackers to execute arbitrary SQL commands via the rsargs array parameter in an expgetFeedContent action.
Affected Software
11 affected components
Gregarius Gregarius=0.3.0
Gregarius Gregarius=0.3.8
Gregarius Gregarius=0.5.2
Gregarius Gregarius=0.5.0
Gregarius Gregarius=0.3.2
Gregarius Gregarius=0.3.6
Gregarius Gregarius=0.2.4
Gregarius Gregarius=0.3.4
Gregarius Gregarius=0.4.2
Gregarius Gregarius=0.4.0
Gregarius Gregarius<=0.5.4
Event History
Jul 30, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3374?
CVE-2008-3374 has a high severity rating due to its potential to allow remote attackers to execute arbitrary SQL commands.
2
How can I fix CVE-2008-3374?
To fix CVE-2008-3374, upgrade to Gregarius version 0.5.5 or later, which contains patches for this vulnerability.
3
What software versions are affected by CVE-2008-3374?
CVE-2008-3374 affects Gregarius versions up to and including 0.5.4.
4
What kind of attacks can CVE-2008-3374 facilitate?
CVE-2008-3374 can facilitate SQL injection attacks, allowing attackers to manipulate the database.
5
What component of Gregarius is vulnerable in CVE-2008-3374?
The vulnerability in CVE-2008-3374 exists in the ajax.php file within Gregarius.