CVE-2008-6381: SQL Injection
SQL injection vulnerability in modules/adresses/viewcat.php in bcoos 1.0.13, and possibly earlier, allows remote authenticated users with Addresses module permissions to execute arbitrary SQL commands via the cid parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6381?
CVE-2008-6381 is considered a high severity vulnerability due to its potential to allow unauthorized SQL commands execution.
How do I fix CVE-2008-6381?
To fix CVE-2008-6381, update to a version of bcoos later than 1.0.13 that addresses this SQL injection vulnerability.
Who is affected by CVE-2008-6381?
CVE-2008-6381 affects remote authenticated users with Addresses module permissions on bcoos versions up to 1.0.13.
What type of vulnerability is CVE-2008-6381?
CVE-2008-6381 is a SQL injection vulnerability that allows execution of arbitrary SQL commands.
Can CVE-2008-6381 be exploited remotely?
Yes, CVE-2008-6381 can be exploited remotely by users with specific permissions in the affected bcoos versions.