CVE-2008-4906: SQL Injection
SQL injection vulnerability in lyricssong.php in the Lyrics (lyricsmenu) plugin 0.42 for e107 allows remote attackers to execute arbitrary SQL commands via the lid parameter. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4906?
The severity of CVE-2008-4906 is considered to be high due to the potential for remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2008-4906?
To fix CVE-2008-4906, update the Lyrics (lyrics_menu) plugin to a version that addresses the SQL injection vulnerability.
What software is affected by CVE-2008-4906?
CVE-2008-4906 affects the Lyrics plugin version 0.4.2 for e107 CMS.
What type of attack does CVE-2008-4906 facilitate?
CVE-2008-4906 facilitates SQL injection attacks, allowing attackers to execute arbitrary SQL commands in the database.
Is there any known exploit for CVE-2008-4906?
Yes, there are known exploits for CVE-2008-4906 that take advantage of the SQL injection vulnerability in the lyrics_song.php file.