CVE-2008-5321: SQL Injection
Published Dec 3, 2008
·Updated
SQL injection vulnerability in index.php in GesGaleri, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the no parameter.
Affected Software
2 affected components
Xoops Hocasi Gesgaleri=_nil_
Xoops Xoops
Event History
Dec 3, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
07:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-5321?
CVE-2008-5321 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2008-5321?
To fix CVE-2008-5321, update GesGaleri to the latest version that addresses the SQL injection issue.
3
What types of attacks can be performed due to CVE-2008-5321?
CVE-2008-5321 allows remote attackers to execute arbitrary SQL commands, potentially compromising the database.
4
Which software is affected by CVE-2008-5321?
CVE-2008-5321 affects the GesGaleri module for XOOPS when utilizing an old version labeled as _nil_.
5
What are the potential impacts of CVE-2008-5321?
Exploitation of CVE-2008-5321 can lead to unauthorized access to sensitive database information.