CVE-2008-6134: SQL Injection
Published Feb 14, 2009
·Updated
SQL injection vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
6 affected components
Drupal EveryBlog=5.0
Drupal EveryBlog=6.0
Drupal Drupal
All of the following
Any of the following
Drupal EveryBlog=5.0
Drupal EveryBlog=6.0
Drupal Drupal
Event History
Feb 14, 2009
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
02:30 AM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·02:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6134?
CVE-2008-6134 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2008-6134?
To fix CVE-2008-6134, upgrade to EveryBlog versions 5.1 or 6.1 or later.
3
Which versions of EveryBlog are affected by CVE-2008-6134?
CVE-2008-6134 affects EveryBlog versions 5.x and 6.x.
4
Can CVE-2008-6134 be exploited remotely?
Yes, CVE-2008-6134 allows remote attackers to execute arbitrary SQL commands.
5
What software contains the CVE-2008-6134 vulnerability?
CVE-2008-6134 is found in the EveryBlog module for Drupal.