First published: Wed Dec 31 2008(Updated: )
SQL injection vulnerability in the eluna Page Comments (eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TYPO3 eluna Page Comments extension | <=1.1.2 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5796 is classified as a high severity vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2008-5796, you should upgrade the eluna Page Comments extension to version 1.1.3 or above.
CVE-2008-5796 affects eluna Page Comments extension versions 1.1.2 and earlier.
Yes, CVE-2008-5796 can be exploited remotely, allowing attackers to execute arbitrary SQL commands.
No, the TYPO3 core is not vulnerable; only the eluna Page Comments extension is affected.