CVE-2008-6647: SQL Injection
Published Apr 7, 2009
·Updated
SQL injection vulnerability in gallery.php in Ktools PhotoStore 3.4.3 allows remote attackers to execute arbitrary SQL commands via the gid parameter.
Affected Software
1 affected component
Ktools Photostore=3.4.3
Event History
Apr 7, 2009
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-6647?
CVE-2008-6647 has a medium severity rating due to its potential to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2008-6647?
To fix CVE-2008-6647, it is recommended to update Ktools PhotoStore to a version that addresses this SQL injection vulnerability.
3
What type of vulnerability is CVE-2008-6647?
CVE-2008-6647 is classified as an SQL injection vulnerability.
4
Which software versions are affected by CVE-2008-6647?
CVE-2008-6647 specifically affects Ktools PhotoStore version 3.4.3.
5
What can attackers do with CVE-2008-6647?
Attackers can exploit CVE-2008-6647 to execute arbitrary SQL commands, potentially compromising the database.