CVE-2008-4494: SQL Injection
Published Oct 8, 2008
·Updated
SQL injection vulnerability in completed-advance.php in TorrentTrader Classic 1.08 and 1.04 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
Affected Software
2 affected components
TorrentTrader TorrentTrader<=1.08
TorrentTrader TorrentTrader=1.04
Event History
Oct 8, 2008
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4494?
CVE-2008-4494 has a moderate severity rating due to its potential for SQL injection attacks.
2
How do I fix CVE-2008-4494?
To fix CVE-2008-4494, you should implement input validation to sanitize the id parameter in completed-advance.php.
3
What versions of TorrentTrader are affected by CVE-2008-4494?
CVE-2008-4494 affects TorrentTrader Classic versions 1.04 and 1.08 and earlier.
4
What type of vulnerability is CVE-2008-4494?
CVE-2008-4494 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
5
Can CVE-2008-4494 lead to data exposure?
Yes, CVE-2008-4494 can potentially allow attackers to gain unauthorized access to sensitive data within the database.