CVE-2008-5196: SQL Injection
Published Nov 21, 2008
·Updated
SQL injection vulnerability in kroax.php in the Kroax (thekroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the category parameter.
Affected Software
2 affected components
PHP-Fusion php-fusion
PHP-Fusion The Kroax Module<=4.42
Event History
Nov 21, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
05:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-5196?
CVE-2008-5196 is classified as a medium severity vulnerability due to its potential to allow remote SQL injection attacks.
2
How do I fix CVE-2008-5196?
To fix CVE-2008-5196, update the Kroax module to a version later than 4.42 to eliminate the SQL injection vulnerability.
3
What systems are affected by CVE-2008-5196?
CVE-2008-5196 affects the Kroax module for PHP-Fusion versions 4.42 and earlier.
4
Can CVE-2008-5196 be exploited remotely?
Yes, CVE-2008-5196 can be exploited remotely by attackers to execute arbitrary SQL commands.
5
What is the category parameter in CVE-2008-5196?
The category parameter in CVE-2008-5196 is a specific input field that is exploited to perform SQL injection attacks.