First published: Tue Nov 04 2008(Updated: )
SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers to execute arbitrary SQL commands via the l_id parameter. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
w1n78 lyrics | =0.4.2 | |
e107 CMS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-4906 is considered to be high due to the potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2008-4906, update the Lyrics (lyrics_menu) plugin to a version that addresses the SQL injection vulnerability.
CVE-2008-4906 affects the Lyrics plugin version 0.4.2 for e107 CMS.
CVE-2008-4906 facilitates SQL injection attacks, allowing attackers to execute arbitrary SQL commands in the database.
Yes, there are known exploits for CVE-2008-4906 that take advantage of the SQL injection vulnerability in the lyrics_song.php file.