CVE-2008-4782: SQL Injection
Published Oct 29, 2008
·Updated
SQL injection vulnerability in public/code/cppollsresults.php in All In One Control Panel (AIOCP) 1.4 allows remote attackers to execute arbitrary SQL commands via the pollid parameter.
Affected Software
2 affected components
AIOCP AIOCP=1.4.000
AIOCP AIOCP=1.4.001
Event History
Oct 29, 2008
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker can exploit the vulnerable poll results endpoint without authentication. The affected input is the poll_id parameter in public/code/cp_polls_results.php.
2
What level of impact could successful exploitation have?
Successful SQL injection can allow execution of arbitrary SQL commands. The supplied severity vector indicates potential impact to confidentiality, integrity, and availability.