CVE-2008-3420: SQL Injection
Multiple SQL injection vulnerabilities in Mobius for Mimsy XG 1 1.4.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to browse.php or (2) the s parameter in an exhibitions action to detail.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3420?
The severity of CVE-2008-3420 is considered high due to the potential for remote SQL command execution.
How do I fix CVE-2008-3420?
To fix CVE-2008-3420, upgrade the Mobius for Mimsy XG software to version 1.4.4.2 or later.
What are the exploitation vectors for CVE-2008-3420?
Exploit vectors for CVE-2008-3420 include manipulating the 'id' parameter in browse.php and the 's' parameter in detail.php.
Who is affected by CVE-2008-3420?
Users of Mobius for Mimsy XG versions 1.4.4.1 and earlier are affected by CVE-2008-3420.
What type of vulnerability is CVE-2008-3420?
CVE-2008-3420 is classified as an SQL injection vulnerability, allowing attackers to execute arbitrary SQL commands.