CVE-2008-5609: SQL Injection
Published Dec 17, 2008
·Updated
SQL injection vulnerability in the Commerce extension 0.9.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
12 affected components
Typo3 TYPO3
Typo3 Commerce extension<=0.9.6
Typo3 Commerce extension=0.8.32
Typo3 Commerce extension=0.8.35
Typo3 Commerce extension=0.9.0
Typo3 Commerce extension=0.9.5
All of the following
Typo3 TYPO3
Any of the following
Typo3 Commerce extension<=0.9.6
Typo3 Commerce extension=0.8.32
Typo3 Commerce extension=0.8.35
Typo3 Commerce extension=0.9.0
Typo3 Commerce extension=0.9.5
Event History
Dec 17, 2008
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
01:30 AM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·01:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-5609?
CVE-2008-5609 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2008-5609?
To fix CVE-2008-5609, upgrade the TYPO3 Commerce extension to version 0.9.7 or later.
3
Which versions of TYPO3 are affected by CVE-2008-5609?
CVE-2008-5609 affects TYPO3 Commerce extension versions 0.9.6 and earlier.
4
Can CVE-2008-5609 lead to data breaches?
Yes, CVE-2008-5609 can allow attackers to execute arbitrary SQL commands, potentially leading to data breaches.
5
What is the impact of CVE-2008-5609 on TYPO3 installations?
CVE-2008-5609 can compromise the integrity and confidentiality of data in affected TYPO3 installations.