CVE-2008-6163: SQL Injection
Published Feb 18, 2009
·Updated
SQL injection vulnerability in www/delivery/ac.php in OpenX 2.6.1 allows remote attackers to execute arbitrary SQL commands via the bannerid parameter.
Affected Software
1 affected component
OpenX OpenX=2.6.1
Remediation
Patch Available
Event History
Feb 18, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Feb 20, 2009
Data Sourced
via NVD·06:46 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6163?
CVE-2008-6163 is considered a high severity SQL injection vulnerability that can lead to arbitrary SQL command execution.
2
How do I fix CVE-2008-6163?
To fix CVE-2008-6163, upgrade OpenX to a version that is not affected by this vulnerability.
3
What software is affected by CVE-2008-6163?
CVE-2008-6163 specifically affects OpenX version 2.6.1.
4
What type of attack is CVE-2008-6163 associated with?
CVE-2008-6163 is associated with SQL injection attacks that exploit the bannerid parameter.
5
Can CVE-2008-6163 be exploited remotely?
Yes, CVE-2008-6163 can be exploited remotely by attackers to execute arbitrary SQL commands.