CVE-2008-6383: SQL Injection
Published Mar 2, 2009
·Updated
SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm project access to execute arbitrary SQL commands via unspecified vectors.
Affected Software
68 affected components
Drupal Storm=5.x-1.1
Drupal Storm=5.x-1.2
Drupal Storm=5.x-1.3
Drupal Storm=5.x-1.4
Drupal Storm=5.x-1.5
Drupal Storm=5.x-1.6
Drupal Storm=5.x-1.7
Drupal Storm=5.x-1.8
Drupal Storm=5.x-1.9
Drupal Storm=5.x-1.10
Drupal Storm=5.x-1.11
Drupal Storm=5.x-1.12
Drupal Storm=5.x-1.13
Drupal Storm=5.x-1.x-dev
Drupal Storm=6.x-1.0
Drupal Storm=6.x-1.1
Drupal Storm=6.x-1.2
Drupal Storm=6.x-1.3
Drupal Storm=6.x-1.4
Drupal Storm=6.x-1.5
Drupal Storm=6.x-1.6
Drupal Storm=6.x-1.7
Drupal Storm=6.x-1.8
Drupal Storm=6.x-1.9
Drupal Storm=6.x-1.10
Drupal Storm=6.x-1.11
Drupal Storm=6.x-1.12
Drupal Storm=6.x-1.13
Drupal Storm=6.x-1.14
Drupal Storm=6.x-1.15
Drupal Storm=6.x-1.16
Drupal Storm=6.x-1.17
Drupal Storm=6.x-1.x-dev
Drupal Drupal
All of the following
Any of the following
Drupal Storm=5.x-1.1
Drupal Storm=5.x-1.2
Drupal Storm=5.x-1.3
Drupal Storm=5.x-1.4
Drupal Storm=5.x-1.5
Drupal Storm=5.x-1.6
Drupal Storm=5.x-1.7
Drupal Storm=5.x-1.8
Drupal Storm=5.x-1.9
Drupal Storm=5.x-1.10
Drupal Storm=5.x-1.11
Drupal Storm=5.x-1.12
Drupal Storm=5.x-1.13
Drupal Storm=5.x-1.x-dev
Drupal Storm=6.x-1.0
Drupal Storm=6.x-1.1
Drupal Storm=6.x-1.2
Drupal Storm=6.x-1.3
Drupal Storm=6.x-1.4
Drupal Storm=6.x-1.5
Drupal Storm=6.x-1.6
Drupal Storm=6.x-1.7
Drupal Storm=6.x-1.8
Drupal Storm=6.x-1.9
Drupal Storm=6.x-1.10
Drupal Storm=6.x-1.11
Drupal Storm=6.x-1.12
Drupal Storm=6.x-1.13
Drupal Storm=6.x-1.14
Drupal Storm=6.x-1.15
Drupal Storm=6.x-1.16
Drupal Storm=6.x-1.17
Drupal Storm=6.x-1.x-dev
Drupal Drupal
Remediation
Patch Available
Patch Available
Event History
Mar 2, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
07:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·07:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6383?
CVE-2008-6383 is classified as a moderate severity SQL injection vulnerability.
2
How do I fix CVE-2008-6383?
To mitigate CVE-2008-6383, upgrade to Storm version 5.x-1.14 or 6.x-1.18 or later.
3
Who is affected by CVE-2008-6383?
CVE-2008-6383 affects authenticated users with storm project access on vulnerable versions of the Drupal Storm module.
4
What kind of attacks can CVE-2008-6383 facilitate?
CVE-2008-6383 allows attackers to execute arbitrary SQL commands, potentially compromising the database.
5
What versions of Storm are affected by CVE-2008-6383?
CVE-2008-6383 affects Storm versions prior to 5.x-1.14 and 6.x-1.18.