First published: Mon Sep 15 2008(Updated: )
SQL injection vulnerability in printfeature.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the artid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP-Nuke | <=1.8.8_8 | |
PHP-Nuke | =1.8.8_7 | |
PHP-Nuke | =1.8.8_8 | |
PHP-Nuke | =1.8.8_8-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4092 is considered a medium severity vulnerability due to its potential for remote SQL injection.
To fix CVE-2008-4092, update myPHPNuke to version 1.8.8_8rc2 or later.
CVE-2008-4092 affects myPHPNuke versions 1.8.8_7, 1.8.8_8-rc1, and all versions prior to 1.8.8_8rc2.
CVE-2008-4092 allows attackers to execute arbitrary SQL commands through the artid parameter.
Yes, CVE-2008-4092 can potentially lead to data loss by allowing attackers to manipulate the database.