CVE-2008-6591: Code Injection
Published Apr 3, 2009
·Updated
LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allows remote attackers to create arbitrary files via the page parameter to (1) index.php and (2) LightNEasy.php.
Affected Software
2 affected components
LightNEasy LightNEasy=1.2.2
LightNEasy LightNEasy=1.2.2
Event History
Apr 3, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6591?
CVE-2008-6591 is considered to be of medium severity due to its potential for remote file creation.
2
How do I fix CVE-2008-6591?
To fix CVE-2008-6591, update to a newer version of LightNEasy that addresses this vulnerability.
3
Which versions of LightNEasy are affected by CVE-2008-6591?
CVE-2008-6591 affects LightNEasy version 1.2.2 and possibly earlier versions.
4
Can CVE-2008-6591 be exploited remotely?
Yes, CVE-2008-6591 can be exploited remotely by attackers to create arbitrary files.
5
What types of attacks are possible with CVE-2008-6591?
CVE-2008-6591 allows attackers to perform unauthorized file creation, which can lead to further system compromises.