First published: Thu Oct 09 2008(Updated: )
SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the kat_id parameter in a kategorier action. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php-fusion Recipes Module | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4527 is rated as a high severity vulnerability due to its potential for unauthorized SQL command execution.
To fix CVE-2008-4527, ensure that user input is properly sanitized and consider upgrading to a patched version of the Recepies module.
CVE-2008-4527 affects the Recepies module version 1.1 for PHP-Fusion.
Yes, CVE-2008-4527 can lead to data breaches as it allows attackers to execute arbitrary SQL commands.
The Recepies module version 1.1 may no longer be actively supported, making it essential to upgrade to more secure alternatives.