First published: Thu Jul 31 2008(Updated: )
SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the r parameter, a different vector than CVE-2006-6115 and CVE-2007-2561.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fipsasp Fipscms Light | <=2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3417 is considered a medium severity SQL injection vulnerability.
To fix CVE-2008-3417, upgrade to a version of fipsCMS Light later than 2.1 that addresses the SQL injection issue.
CVE-2008-3417 allows remote attackers to execute arbitrary SQL commands, potentially compromising the database integrity.
CVE-2008-3417 affects fipsCMS Light version 2.1 and earlier.
CVE-2008-3417 is a different vector than CVE-2006-6115 and CVE-2007-2561, although they all pertain to SQL injection.