First published: Fri Nov 21 2008(Updated: )
SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the category parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins | ||
Php-fusion The Kroax Module | <=4.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5196 is classified as a medium severity vulnerability due to its potential to allow remote SQL injection attacks.
To fix CVE-2008-5196, update the Kroax module to a version later than 4.42 to eliminate the SQL injection vulnerability.
CVE-2008-5196 affects the Kroax module for PHP-Fusion versions 4.42 and earlier.
Yes, CVE-2008-5196 can be exploited remotely by attackers to execute arbitrary SQL commands.
The category parameter in CVE-2008-5196 is a specific input field that is exploited to perform SQL injection attacks.