CVE-2008-4785: SQL Injection
SQL injection vulnerability in newuser.php in the alternateprofiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4785?
CVE-2008-4785 is considered a critical SQL injection vulnerability due to its potential for remote exploitation.
How do I fix CVE-2008-4785?
To fix CVE-2008-4785, update the alternate_profiles plugin to a later, secure version that has patched this vulnerability.
What are the consequences of exploiting CVE-2008-4785?
Exploiting CVE-2008-4785 allows attackers to execute arbitrary SQL commands, which can compromise the database and application integrity.
Which versions of the e107 CMS are affected by CVE-2008-4785?
CVE-2008-4785 specifically affects the 0.2 version of the alternate_profiles plugin for e107.
Is it possible to mitigate CVE-2008-4785 without an update?
Mitigation for CVE-2008-4785 is limited; the best solution is to update to a secure version of the affected plugin.