CVE-2008-6189: SQL Injection
Published Feb 19, 2009
·Updated
SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php.
Affected Software
1 affected component
GForge=4.5.19
Event History
Feb 19, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6189?
CVE-2008-6189 is considered a critical vulnerability due to its potential for remote SQL injection attacks.
2
How does CVE-2008-6189 exploit the GForge application?
CVE-2008-6189 allows remote attackers to execute arbitrary SQL commands via the offset parameter in specific PHP scripts.
3
What versions of GForge are affected by CVE-2008-6189?
CVE-2008-6189 affects GForge version 4.5.19.
4
How can I fix CVE-2008-6189 in my GForge application?
To fix CVE-2008-6189, apply patches released by the GForge maintainers or upgrade to a secure version.
5
What are the potential impacts of exploiting CVE-2008-6189?
Exploiting CVE-2008-6189 can lead to unauthorized access to the database, data corruption, or data leakage.