CVE-2008-6418: SQL Injection
Published Mar 6, 2009
·Updated
SQL injection vulnerability in scrape.php in TorrentTrader before 2008-05-13 allows remote attackers to execute arbitrary SQL commands via the infohash parameter.
Affected Software
4 affected components
TorrentTrader TorrentTrader=1.07
TorrentTrader TorrentTrader=1.08
TorrentTrader TorrentTrader=1.0
TorrentTrader TorrentTrader=1.06
Remediation
Patch Available
Event History
Mar 6, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6418?
CVE-2008-6418 is classified as a critical severity vulnerability due to the potential for arbitrary SQL command execution.
2
How do I fix CVE-2008-6418?
To fix CVE-2008-6418, update TorrentTrader to version 1.08 or later, which addresses the SQL injection vulnerability.
3
What software is affected by CVE-2008-6418?
CVE-2008-6418 affects TorrentTrader versions 1.0, 1.06, 1.07, and 1.08 before a certain patch.
4
What type of vulnerability is CVE-2008-6418?
CVE-2008-6418 is an SQL injection vulnerability that allows attackers to execute arbitrary commands in the database.
5
Can CVE-2008-6418 be exploited remotely?
Yes, CVE-2008-6418 can be exploited remotely through malicious requests to the affected application.