CVE-2008-4627: SQL Injection
SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execute arbitrary SQL commands via the itemID parameter in the RGalleryImageWrapper page in index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4627?
CVE-2008-4627 is considered a high severity vulnerability due to its potential for remote SQL command execution.
How do I fix CVE-2008-4627?
To fix CVE-2008-4627, update the rGallery plugin to a version that is not affected, or implement input validation to sanitize the itemID parameter.
What software is affected by CVE-2008-4627?
CVE-2008-4627 affects the rGallery plugin version 1.09 specifically designed for the WoltLab Burning Board.
Can CVE-2008-4627 be exploited remotely?
Yes, CVE-2008-4627 can be exploited remotely, allowing attackers to execute arbitrary SQL commands.
What is the impact of CVE-2008-4627?
The impact of CVE-2008-4627 can include unauthorized access to the database, data manipulation, and potential application compromise.