CVE-2008-4656: SQL Injection
Published Oct 21, 2008
·Updated
SQL injection vulnerability in the Frontend Users View (feusersview) 0.1.6 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
4 affected components
Typo3 Frontend Users View<=0.1.6
Typo3 Frontend Users View=0.1.2
Typo3 Frontend Users View=0.1.3
Typo3 TYPO3
Event History
Oct 21, 2008
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Oct 22, 2008
Data Sourced
12:11 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-4656?
CVE-2008-4656 has a high severity rating due to its potential to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2008-4656?
To fix CVE-2008-4656, upgrade the TYPO3 Frontend Users View extension to version 0.1.7 or later.
3
Which versions of TYPO3 are affected by CVE-2008-4656?
CVE-2008-4656 affects TYPO3 Frontend Users View versions up to and including 0.1.6.
4
What type of vulnerability is CVE-2008-4656?
CVE-2008-4656 is an SQL injection vulnerability.
5
Can CVE-2008-4656 be exploited through user input?
Yes, CVE-2008-4656 can be exploited through unspecified vectors that include user input.