CVE-2008-5074: SQL Injection
Published Nov 14, 2008
·Updated
SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the linkid parameter.
Affected Software
2 affected components
PHP-Fusion Freshlinks Module=1.0-rc1
PHP-Fusion php-fusion
Event History
Nov 14, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
06:07 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-5074?
CVE-2008-5074 is classified as a high severity vulnerability due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2008-5074?
To fix CVE-2008-5074, update your Freshlinks module to a version that patches this SQL injection vulnerability.
3
Which software versions are affected by CVE-2008-5074?
CVE-2008-5074 specifically affects Freshlinks module version 1.0 RC1 for PHP-Fusion.
4
Can CVE-2008-5074 be exploited remotely?
Yes, CVE-2008-5074 can be exploited remotely, allowing attackers to execute arbitrary SQL commands.
5
What is the impact of exploiting CVE-2008-5074?
Exploiting CVE-2008-5074 can lead to unauthorized access to the database and manipulation of sensitive data.