CVE-2008-4092: SQL Injection
Published Sep 15, 2008
·Updated
SQL injection vulnerability in printfeature.php in myPHPNuke (MPN) before 1.8.88rc2 allows remote attackers to execute arbitrary SQL commands via the artid parameter.
Affected Software
4 affected components
myPHPNuke myPHPNuke<=1.8.8_8
myPHPNuke myPHPNuke=1.8.8_7
myPHPNuke myPHPNuke=1.8.8_8
myPHPNuke myPHPNuke=1.8.8_8-rc1
Event History
Sep 15, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4092?
CVE-2008-4092 is considered a medium severity vulnerability due to its potential for remote SQL injection.
2
How do I fix CVE-2008-4092?
To fix CVE-2008-4092, update myPHPNuke to version 1.8.8_8rc2 or later.
3
Which versions of myPHPNuke are affected by CVE-2008-4092?
CVE-2008-4092 affects myPHPNuke versions 1.8.8_7, 1.8.8_8-rc1, and all versions prior to 1.8.8_8rc2.
4
What type of attack is possible with CVE-2008-4092?
CVE-2008-4092 allows attackers to execute arbitrary SQL commands through the artid parameter.
5
Can CVE-2008-4092 lead to data loss?
Yes, CVE-2008-4092 can potentially lead to data loss by allowing attackers to manipulate the database.