CVE-2008-4657: SQL Injection
Published Oct 21, 2008
·Updated
SQL injection vulnerability in the Econda Plugin (econda) 0.0.2 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
3 affected components
Typo3 Econda Plugin<=0.0.2
Typo3 Econda Plugin=0.0.1
Typo3 TYPO3
Remediation
Patch Available
Patch Available
Event History
Oct 21, 2008
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Oct 22, 2008
Data Sourced
12:11 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-4657?
CVE-2008-4657 has a medium severity rating due to its potential for remote SQL injection.
2
How do I fix CVE-2008-4657?
To resolve CVE-2008-4657, upgrade the Econda Plugin for TYPO3 to version 0.0.4 or later.
3
What software is affected by CVE-2008-4657?
CVE-2008-4657 affects the Econda Plugin versions 0.0.2 and earlier for TYPO3.
4
Can CVE-2008-4657 be exploited remotely?
Yes, CVE-2008-4657 can be exploited remotely by attackers to execute arbitrary SQL commands.
5
Is there a patch available for CVE-2008-4657?
Yes, the patch for CVE-2008-4657 is included in the updated Econda Plugin version 0.0.4.