CVE-2008-5882: SQL Injection
SQL injection vulnerability in login.asp in Citrix Application Gateway - Broadcast Server (BCS) before 6.1, as used by Avaya AG250 - Broadcast Server before 2.0 and possibly other products, allows remote attackers to execute arbitrary SQL commands via the txtUID parameter.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5882?
CVE-2008-5882 is categorized as a high severity SQL injection vulnerability.
How do I fix CVE-2008-5882?
To remediate CVE-2008-5882, update to Citrix Broadcast Server version 6.1 or later, or Avaya Broadcast Server version 2.0 or later.
Who is affected by CVE-2008-5882?
CVE-2008-5882 affects Citrix Broadcast Server versions prior to 6.1 and Avaya Broadcast Server versions prior to 2.0.
What type of vulnerability is CVE-2008-5882?
CVE-2008-5882 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
Can CVE-2008-5882 be exploited remotely?
Yes, CVE-2008-5882 can be exploited remotely by attackers through the txtUID parameter.