First published: Fri Feb 06 2009(Updated: )
SQL injection vulnerability in e107chat.php in the eChat plugin 4.2 for e107, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
123 Flash Chat | =4.2 | |
e107 CMS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6069 is considered a high severity vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2008-6069, ensure that magic_quotes_gpc is enabled and consider upgrading to a patched version of the eChat plugin.
CVE-2008-6069 specifically affects version 4.2 of the eChat plugin for e107.
CVE-2008-6069 is an SQL injection vulnerability that allows attackers to manipulate database queries.
While e107 CMS itself is not vulnerable, using the eChat plugin version 4.2 poses security risks if it remains unpatched.