CVE-2008-4088: SQL Injection
Published Sep 15, 2008
·Updated
SQL injection vulnerability in print.php in myPHPNuke (MPN) before 1.8.88rc2 allows remote attackers to execute arbitrary SQL commands via the sid parameter.
Affected Software
4 affected components
myPHPNuke myPHPNuke<=1.8.8_8
myPHPNuke myPHPNuke=1.8.8_7
myPHPNuke myPHPNuke=1.8.8_8
myPHPNuke myPHPNuke=1.8.8_8-rc1
Event History
Sep 15, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4088?
CVE-2008-4088 has a medium severity rating due to its potential to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2008-4088?
To fix CVE-2008-4088, upgrade to myPHPNuke version 1.8.8_8 or later.
3
Which versions of myPHPNuke are affected by CVE-2008-4088?
CVE-2008-4088 affects versions 1.8.8_7, 1.8.8_8-rc1, and earlier versions up to 1.8.8_8.
4
What type of vulnerability is CVE-2008-4088?
CVE-2008-4088 is an SQL injection vulnerability.
5
Can CVE-2008-4088 be exploited remotely?
Yes, CVE-2008-4088 can be exploited remotely by attackers targeting the sid parameter.